-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 18 Dec 2024 17:11:25 +0100 Source: rsync Binary: rsync rsync-dbgsym Architecture: s390x Version: 3.2.7-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Salvatore Bonaccorso Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Some checksum buffer fixes. (CVE-2024-12084) * Another cast when multiplying integers. (CVE-2024-12084) * prevent information leak off the stack (CVE-2024-12085) * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) * added secure_relative_open() (CVE-2024-12086) * receiver: use secure_relative_open() for basis file (CVE-2024-12086) * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) * Refuse a duplicate dirlist. (CVE-2024-12087) * range check dir_ndx before use (CVE-2024-12087) * make --safe-links stricter (CVE-2024-12088) * fixed symlink race condition in sender (CVE-2024-12747) * raise protocol version to 32 Checksums-Sha1: 7ebd55c002c696f38f519abdbeb73b64159846fc 504728 rsync-dbgsym_3.2.7-1+deb12u1_s390x.deb b216e5e0c37220d7cfa52eac8f2bdcb824d658a6 6761 rsync_3.2.7-1+deb12u1_s390x-buildd.buildinfo 3e95de4cbd5cdc001fa063caa72e9d38a05814d7 399596 rsync_3.2.7-1+deb12u1_s390x.deb Checksums-Sha256: 398a57a7da8b58d69242f25c1abad448047a8f9cf2cc5fdd70900ff5afa7dd09 504728 rsync-dbgsym_3.2.7-1+deb12u1_s390x.deb 2b676d9b5c8a8d9edb338636c75571e44766f7b9fa61f78ee58565eef94453f0 6761 rsync_3.2.7-1+deb12u1_s390x-buildd.buildinfo 9b29d64b46970ca3fed68f02054d4b14b7e99e1850e8a39c6d64a493fb2a598d 399596 rsync_3.2.7-1+deb12u1_s390x.deb Files: 40a6cedd10c1a78da2144867bbbd3c45 504728 debug optional rsync-dbgsym_3.2.7-1+deb12u1_s390x.deb 8bd4046fe548eed0f78cd9c2bf81d4cd 6761 net optional rsync_3.2.7-1+deb12u1_s390x-buildd.buildinfo 07ca2f2254a22812b9d068964159d664 399596 net optional rsync_3.2.7-1+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEu0D/YpnnSxv8epH9AKOyQzsWVasFAmd4WisACgkQAKOyQzsW VavDIRAAtJ1Gmto1QDG9LJ2svrFG6akOjIjsWoxkXQL80Le76WXq3JrgMwYRBbuZ VWnabdmRq3kit3h/9MBjvQCYaxUXcLg4sEt5V6Pykq178/7ryZ9JAxV4F/LgwZs6 0vZ/bpfdvAy673A3ZJ+/Crx2k0hYDHfle9lfDsQYbjrO93O5LQfPF2fcPtM8SoaS Byd6Sx1B+dteYAQoPm2smbU/CIfBuKCra0sBG2yaoa7GP1v6OgH+2cpHu43/HjsF oK2Xs3QlcnBYnzQhrFjiOdqA4CSdTXRq/rkyVXJb6iN389imHWCYlH7QyasFk1EJ KFyIbmvHY+e6m2BQfl5lSkWrkEUCHLlUyO3VOJRjJukL8G6NVfni+qMcD7fxb+6f 80bO4LPL02XqQhqJOayZ20VbtS+SjEDPkNjFwgry0QMn51rC4cpqmXVQ8rgkm6kB 9wu4hequQJTh9pkvY1gvqrSZC2JKWO2kwB3CP/Z50YWjlkt75JV6luVmX37KW+Jo SKfLJGkKIXX+FiE81A5qiMbU8AEdfpBOXbmQSIxco6kYARQhGevrK0n/QcfXi2vW BplddBQLP3gsJLLCdiAQrAsULD8g1WRyykJylDiGBOtNEJbcg0eZVBcT++yLjb/f xzaEQlAp64n/ZpliUfNNN/fvuRR7qLzznPmhUE+afdCQ6qA294c= =bIhF -----END PGP SIGNATURE-----