rsync-3.2.3-20.el9_5.1

エラータID: AXSA:2025-9542:01

Release date: 
Thursday, January 16, 2025 - 10:55
Subject: 
rsync-3.2.3-20.el9_5.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

* rsync: Info Leak via Uninitialized Stack Contents (CVE-2024-12085)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-12085
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rsync-3.2.3-20.el9_5.1.src.rpm
    MD5: 6479f23b409a2b9c79fa121e5c4b786c
    SHA-256: 4c648f75e427354e45bf471043ca6d3b11aeb1c104f14ec67af7274363908838
    Size: 1.22 MB

Asianux Server 9 for x86_64
  1. rsync-3.2.3-20.el9_5.1.x86_64.rpm
    MD5: 688348a7d559fac4a74d3ac1d500343a
    SHA-256: 4ca3f3de4f8b71c033c0ae9756cf79bbcb668674d982a9314230188c8fddf074
    Size: 398.99 kB
  2. rsync-daemon-3.2.3-20.el9_5.1.noarch.rpm
    MD5: efd77cad807f0befacd3d3f6eab7ca8a
    SHA-256: b77cedf31f1e0419321eb3fdba0f79be66a635a8a992de1bbbd4420e186165d4
    Size: 8.57 kB