-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 18 Dec 2024 17:11:25 +0100 Source: rsync Binary: rsync rsync-dbgsym Architecture: arm64 Version: 3.2.7-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Salvatore Bonaccorso Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Some checksum buffer fixes. (CVE-2024-12084) * Another cast when multiplying integers. (CVE-2024-12084) * prevent information leak off the stack (CVE-2024-12085) * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) * added secure_relative_open() (CVE-2024-12086) * receiver: use secure_relative_open() for basis file (CVE-2024-12086) * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) * Refuse a duplicate dirlist. (CVE-2024-12087) * range check dir_ndx before use (CVE-2024-12087) * make --safe-links stricter (CVE-2024-12088) * fixed symlink race condition in sender (CVE-2024-12747) * raise protocol version to 32 Checksums-Sha1: 604e3338c7d154861fd0293390a5e8cbb2d93868 514284 rsync-dbgsym_3.2.7-1+deb12u1_arm64.deb 5ea28bd0215129318a6927a8a346cd584a5be9c5 6865 rsync_3.2.7-1+deb12u1_arm64-buildd.buildinfo 89cf8fb253e496527054033b5184da60c4e252df 400476 rsync_3.2.7-1+deb12u1_arm64.deb Checksums-Sha256: ca9c919bbaf498d1d2d4a59b7afac44dc5ba875049cd24aa19b2cb07163c829e 514284 rsync-dbgsym_3.2.7-1+deb12u1_arm64.deb 0540ea710cdff0767d2c99dd93655239d8fef6600b749ae2c8916805a19b166a 6865 rsync_3.2.7-1+deb12u1_arm64-buildd.buildinfo b8988ae02c73d2b4d3838360d4e3d69d15bc5d439a7784b478af3d168775174c 400476 rsync_3.2.7-1+deb12u1_arm64.deb Files: 2a2ac965c3948d852ff8d27fafa010f2 514284 debug optional rsync-dbgsym_3.2.7-1+deb12u1_arm64.deb 57b03b8b98d791f8793f221ac0d8f4b8 6865 net optional rsync_3.2.7-1+deb12u1_arm64-buildd.buildinfo a9b96c9c1a0b073d51401dfc44e78fac 400476 net optional rsync_3.2.7-1+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEH43oX1cK+BEEs9Pe/9j0ct/+ZwwFAmd4WIEACgkQ/9j0ct/+ ZwzvaxAAt3JxBNULgrjjz6TqOD3OP5BIjYT6svV6QixQFVVXuVgIWpjlFI9Y5YSX 0tFudKPmzgeU9gW/c5hA9cETXw1jWkVGMv7OQFXhBJxs7yTwHBwjSbSJ1cOg3A9F /0SZLYl/Lz/NMGEgIW4hEbK1m8Q5wMOswJ3MXHUPmJfI5NX3suvf+MZ9HQP3C7+W SdfL3lz2tvCLWDKlNJ72bLw8rdsWuI8qgKX1Uz7KArWwpINWgS151xAVr8IoAPeT jbrzNjVVIiXX0SM2Nu5n72ACU4KIMvrtjANQ1YGy6JUrNBpVyU1/j1xMLso34pU2 mkXszinpexVBWjLPtubyXCax9t26wfzbA4QgzO8pOAmIXa2IjNvHhCqB5sJbI4V3 3BCa8A2WNArjMGp7OsnUo+keHBhR8obOV3VjSHGwsVjrH6fumvh/InPclK+qlJ/X txPEObfTB/HgdfrtMnrNRyrO/NuDBlW7ZFDVN+FNb5NkuYyzX/OOujUQQ2favNNE OzZLIKSY+1usQWSTfkDxFdDUGrSoLLrPdIfh5NtjQUwQuYaOzzhHPMS5Q2VSHPry IlMswMvT3H/ejCJRY5WntitHM1lvFwDUEBl9lWJVwokBfakdqtYZCYNsxtt8EM5/ jggHB2/euFSxfYt/ahHGQUTJnNaf8mlmdrX2vTP0T1tthwDzRqg= =z54/ -----END PGP SIGNATURE-----