-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 18 Dec 2024 17:11:25 +0100 Source: rsync Binary: rsync rsync-dbgsym Architecture: mipsel Version: 3.2.7-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Salvatore Bonaccorso Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Some checksum buffer fixes. (CVE-2024-12084) * Another cast when multiplying integers. (CVE-2024-12084) * prevent information leak off the stack (CVE-2024-12085) * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) * added secure_relative_open() (CVE-2024-12086) * receiver: use secure_relative_open() for basis file (CVE-2024-12086) * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) * Refuse a duplicate dirlist. (CVE-2024-12087) * range check dir_ndx before use (CVE-2024-12087) * make --safe-links stricter (CVE-2024-12088) * fixed symlink race condition in sender (CVE-2024-12747) * raise protocol version to 32 Checksums-Sha1: bd74d89f0e7c6ce21340657a997f922ebbc908c7 532720 rsync-dbgsym_3.2.7-1+deb12u1_mipsel.deb 2c0d3fece86db90ccad3738c7332d9d1fd2a4f21 6695 rsync_3.2.7-1+deb12u1_mipsel-buildd.buildinfo 309513f55cabad8f5ab9a81d80ffc1ab10349b11 407760 rsync_3.2.7-1+deb12u1_mipsel.deb Checksums-Sha256: a0ad78c9b6462be86d19beb35a2c960797191e0372169e9ef6b485d55c26e9a4 532720 rsync-dbgsym_3.2.7-1+deb12u1_mipsel.deb abc33aab77be1d47abf3514361b2a9480716665cf829f53ac839227f62570e53 6695 rsync_3.2.7-1+deb12u1_mipsel-buildd.buildinfo 53589955dacf8450cde93108dfdaefeac31cbf24e7f9378d8525334655f5abd4 407760 rsync_3.2.7-1+deb12u1_mipsel.deb Files: 5544c202965ac053af21cde88924e132 532720 debug optional rsync-dbgsym_3.2.7-1+deb12u1_mipsel.deb 056e7acbf3d410ba4b37a10c33639c48 6695 net optional rsync_3.2.7-1+deb12u1_mipsel-buildd.buildinfo 9cf16938638a3d0dd3192d0c554266a6 407760 net optional rsync_3.2.7-1+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmd4X+IACgkQlmZGXOM8 3t8fvQ//fZTYmGqHO3gWCN/xpQgORzEG+PxUlYlwuNlO5Y51lTdLpQyRZrmpk2O9 rX7j731tKXtr/W1gEfkuRiXuv6te+DQMSYo8BipvpR0aTkyswxYJAL6+IX8W2oGH 1K5VMqgK1aH6CoO3ds7ipoPtf3hmOjdRDciqar69ZGYSaD337sv5unljIca7072X HGP7szyBIBFPAlg92qOM9aanoLUq4emQ+NMatAaqO3jWsp27NqV4eAp/5Nv0ut7F ID3YvEd7kmrvO/0IJEXDTeLqsor9iXGDHMBSSrS2O4TNvH/N5glZJ9Qo8hhwSdVE XQKSv0YUd5ab2ZDNLFs0O8n4QQvyfdpDmdLNTV+Dx5ELeFW488CCIzCID7HVdVAh sBxWESADQtopPrwusPj8kxmv7RFX2ycAmicKUlzi1mitxhRPwUCb5PkDOuxG9qEO ZnzC4x4DjI8em0PpmsqsWI0tQFKL2XUCeRhsTXauLJ7HXWjfXjjYh0rCuSvpRRv4 JUmL7HbmorpDDjm8Y/CLrli6Jx3435b7/YqSw0xdlwl7LHfkI4OcT10HoxQjMzrJ zcKhlGpqZw9TTrKmWLlD/crB1IQac1vHaV6ofWk5WzVUI4q/juLtLfIduGk9z08w 1y9hiGcYpZLv3IUQzD1KBk/2ywiD9U9vqah9Q/j49pjGAZ7gWPs= =NFoW -----END PGP SIGNATURE-----