Heap buffer overflow in rsync due to improper checksum length handling. (CVE-2024-12084) Info leak via uninitialized stack contents. (CVE-2024-12085) Rsync server leaks arbitrary client files. (CVE-2024-12086) Path traversal vulnerability in rsync. (CVE-2024-12087) . MGASA-2025-0019 - Updated rsync packages fix security vulnerabilities Publication date: 22 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0019.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747 Heap buffer overflow in rsync due to improper checksum length handling. (CVE-2024-12084) Info leak via uninitialized stack contents. (CVE-2024-12085) Rsync server leaks arbitrary client files. (CVE-2024-12086) Path traversal vulnerability in rsync. (CVE-2024-12087) Rsync --safe-links option bypass leads to path traversal. (CVE-2024-12088) Race condition in rsync handling symbolic links. (CVE-2024-12747) References: - https://bugs.mageia.org/show_bug.cgi?id=33920 - https://www.openwall.com/lists/oss-security/2025/01/14/3 - https://lists.debian.org/debian-security-announce/2025/msg00004.html - https://ubuntu.com/security/notices/USN-7206-1 - https://ubuntu.com/security/notices/USN-7206-2 - https://www.cve.org/CVERecord?id=CVE-2024-12084 - https://www.cve.org/CVERecord?id=CVE-2024-12085 - https://www.cve.org/CVERecord?id=CVE-2024-12086 - https://www.cve.org/CVERecord?id=CVE-2024-12087 - https://www.cve.org/CVERecord?id=CVE-2024-12088 - https://www.cve.org/CVERecord?id=CVE-2024-12747 SRPMS: - 9/core/rsync-3.2.7-1.2.mga9 . Enhanced rsync software in Mageia 2025-0019 resolves several vulnerabilities such as buffer overflow and directory traversal risk.. Rsync Vulnerabilities, Mageia Security Update, Buffer Overflow Fixes. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.