Explore top 10 tips to secure your open-source projects now. Read More
×* bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 . # Security update for rsync Announcement ID: SUSE-SU-2025:20223-1 Release Date: 2025-02-07T09:57:24Z Rating: critical References: * bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 * bsc#1235475 Cross-References: * CVE-2024-12084 * CVE-2024-12085 * CVE-2024-12086 * CVE-2024-12087 * CVE-2024-12088 * CVE-2024-12747 CVSS scores: * CVE-2024-12084 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12084 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12085 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12085 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-12085 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-12086 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12086 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-12086 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2024-12087 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12087 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-12087 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-12088 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12747 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2024-12747 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-12747 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: *SUSE Linux Micro 6.1 An update that solves six vulnerabilities can now be installed. ## Description: This update for rsync fixes the following issues: * Bump protocol version to 32 - make it easier to show server is patched. * Fix FLAG_GOT_DIR_FLIST collission with FLAG_HLINKED * Security update,CVE-2024-12747, bsc#1235475 race condition in handling symbolic links * Security update, fix multiple vulnerabilities: * CVE-2024-12084, bsc#1234100 - Heap Buffer Overflow in Checksum Parsing * CVE-2024-12085, bsc#1234101 - Info Leak via uninitialized Stack contents defeats ASLR * CVE-2024-12086, bsc#1234102 - Server leaks arbitrary client files * CVE-2024-12087, bsc#1234103 - Server can make client write files outside of destination directory using symbolic links * CVE-2024-12088, bsc#1234104 - --safe-links Bypass ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-15=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * rsync-debugsource-3.3.0-slfo.1.1_3.1 * rsync-3.3.0-slfo.1.1_3.1 * rsync-debuginfo-3.3.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12084.html * https://www.suse.com/security/cve/CVE-2024-12085.html * https://www.suse.com/security/cve/CVE-2024-12086.html * https://www.suse.com/security/cve/CVE-2024-12087.html * https://www.suse.com/security/cve/CVE-2024-12088.html * https://www.suse.com/security/cve/CVE-2024-12747.html * https://bugzilla.suse.com/show_bug.cgi?id=1234100 * https://bugzilla.suse.com/show_bug.cgi?id=1234101 * https://bugzilla.suse.com/show_bug.cgi?id=1234102 * https://bugzilla.suse.com/show_bug.cgi?id=1234103 * https://bugzilla.suse.com/show_bug.cgi?id=1234104 * https://bugzilla.suse.com/show_bug.cgi?id=1235475 . Urgent patchreleased for openssl addresses various high-severity vulnerabilities affecting Fedora. Immediate implementation advised.. rsync security update, SUSE Linux patch, file transfer vulnerabilities, critical security risks. . Severity: Critical. LinuxSecurity.com Team
fix zlib source path in patch file. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6f6043cb99 2025-05-23 03:24:17.285913+00:00 -------------------------------------------------------------------------------- Name : zsync Product : Fedora 42 Version : 0.6.2 Release : 3.fc42 URL : http://zsync.moria.org.uk/ Summary : a file transfer program using the same algorithm as rsync over HTTP Description : zsync is a file transfer program. It allows you to download a file from a remote server, where you have a copy of an older version of the file on your computer already. zsync downloads only the new parts of the file. It uses the same algorithm as rsync. However, where rsync is designed for synchronising data from one computer to another within an organisation, zsync is designed for file distribution, with one file on a server to be distributed to thousands of downloaders. zsync requires no special server software - just a web server to host the files - and imposes no extra load on the server, making it ideal for large scale file distribution. -------------------------------------------------------------------------------- Update Information: fix zlib source path in patch file -------------------------------------------------------------------------------- ChangeLog: * Thu May 15 2025 Tobias Girstmair - 0.6.2-3 - fix zlib source path in patch file * Thu May 15 2025 Tobias Girstmair - 0.6.2-2 - include a patch for CVE-2016-9840 (RHBZ#2366435) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2366435 - CVE-2025-4638 zsync: Improper Pointer Arithmetic in pcl [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366435 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-6f6043cb99' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for CVE-2024-31497. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-8401d42de6 2024-04-18 01:11:31.874318 -------------------------------------------------------------------------------- Name : filezilla Product : Fedora 39 Version : 3.67.0 Release : 1.fc39 URL : https://filezilla-project.org/ Summary : FTP, FTPS and SFTP client Description : FileZilla is a FTP, FTPS and SFTP client for Linux with a lot of features. - Supports FTP, FTP over SSL/TLS (FTPS) and SSH File Transfer Protocol (SFTP) - Cross-platform - Available in many languages - Supports resume and transfer of large files greater than 4GB - Easy to use Site Manager and transfer queue - Drag & drop support - Speed limits - Filename filters - Network configuration wizard -------------------------------------------------------------------------------- Update Information: Fix for CVE-2024-31497 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 15 2024 Gwyn Ciesla - 3.67.0-1 - 3.67.0 * Mon Apr 15 2024 Gwyn Ciesla - 3.66.5-2 - libfilezilla rebuild * Wed Feb 7 2024 Gwyn Ciesla - 3.66.5-1 - 3.66.5 * Wed Jan 24 2024 Fedora Release Engineering - 3.66.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 3.66.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2275187 - CVE-2024-31497 filezilla: putty: secret key recovery of NIST P-521 private keys Through Biased ECDSA Nonces in PuTTY Client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2275187 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-8401d42de6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
croc 9.6.4. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-ac4651c9b2 2023-07-04 01:32:56.926315 --------------------------------------------------------------------------------Name : golang-github-schollz-croc Product : Fedora 38 Version : 9.6.4 Release : 2.fc38 URL : https://github.com/schollz/croc Summary : Easily and securely send things from one computer to another Description : croc is a tool that allows any two computers to simply and securely transfer files and folders. --------------------------------------------------------------------------------Update Information: croc 9.6.4 --------------------------------------------------------------------------------ChangeLog: * Sun Jun 25 2023 Davide Cavalca - 9.6.4-2 - Gate out broken test on s390x for f38 * Fri May 19 2023 Mikel Olasagasti Uranga - 9.6.4-1 - Update to 9.6.4 - Closes rhbz#2208585 rhbz#2171537 rhbz#2163218 * Thu Jan 19 2023 Fedora Release Engineering - 9.5.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Thu Jul 21 2022 Fedora Release Engineering - 9.5.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Tue Jul 19 2022 Maxwell G - 9.5.2-2 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------References: [ 1 ] Bug #2163218 - CVE-2022-41717 golang-github-schollz-croc: golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2163218 [ 2 ] Bug #2171537 - golang-github-schollz-croc: FTBFS in Fedora rawhide/f38 https://bugzilla.redhat.com/show_bug.cgi?id=2171537 [ 3 ] Bug #2208585 - golang-github-schollz-croc-9.6.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2208585 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ac4651c9b2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- update to the latest upstream release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-645497fb95 2022-09-12 17:36:48.816207 --------------------------------------------------------------------------------Name : curl Product : Fedora 37 Version : 7.84.0 Release : 3.fc37 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. --------------------------------------------------------------------------------Update Information: - update to the latest upstream release --------------------------------------------------------------------------------ChangeLog: * Thu Aug 25 2022 Kamil Dudka - 7.84.0-3 - tests: fix http2 tests to use CRLF headers to make it work with nghttp2-1.49.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #2120533 - nghttp2-1.49.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2120533 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-645497fb95' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Moderate: curl security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:6159', 'synopsis': 'Moderate: curl security update', 'severity': 'Moderate', 'topic': 'An update for curl is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2099300', '2099306'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-32206.json:::CVE-2022-32206', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-32208.json:::CVE-2022-32208'], 'references': [], 'publishedAt': '2022-08-29T22:14:20.960911Z', 'rpms': ['curl-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-7.61.1-22.el8_6.4.src.rpm', 'curl-7.61.1-22.el8_6.4.x86_64.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.i686.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-devel-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-devel-7.61.1-22.el8_6.4.i686.rpm','libcurl-devel-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm']}\. Rocky Linux has released a security advisory regarding a moderate curl update that affects file transfer operations, enhancing protection against potential vulnerabilities. Rocky Linux Curl Update, Linux Server Security Patches, Moderate Risk Advisory. . LinuxSecurity.com Team
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-schollz-croc Product : Fedora 36 Version : 9.5.2 Release : 2.fc36 URL : https://github.com/schollz/croc Summary : Easily and securely send things from one computer to another Description : croc is a tool that allows any two computers to simply and securely transfer files and folders. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 9.5.2-2 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An issues has been found in lrzsz, a set of tools for zmodem/xmodem/ymodem file transfer. Due to an incorrect length check, which might result in a size_t wrap . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2900-1
Get the latest Linux and open source security news straight to your inbox.