-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 18 Dec 2024 17:11:25 +0100 Source: rsync Binary: rsync rsync-dbgsym Architecture: ppc64el Version: 3.2.7-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Salvatore Bonaccorso Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Some checksum buffer fixes. (CVE-2024-12084) * Another cast when multiplying integers. (CVE-2024-12084) * prevent information leak off the stack (CVE-2024-12085) * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) * added secure_relative_open() (CVE-2024-12086) * receiver: use secure_relative_open() for basis file (CVE-2024-12086) * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) * Refuse a duplicate dirlist. (CVE-2024-12087) * range check dir_ndx before use (CVE-2024-12087) * make --safe-links stricter (CVE-2024-12088) * fixed symlink race condition in sender (CVE-2024-12747) * raise protocol version to 32 Checksums-Sha1: 27ffacd2d4a16fc206ddf6d05497cc57ebcb5134 529492 rsync-dbgsym_3.2.7-1+deb12u1_ppc64el.deb ecf040b98629076e0b3a99ed12e06217f470d65b 6878 rsync_3.2.7-1+deb12u1_ppc64el-buildd.buildinfo 6bcaf8afb88b7653ae504354d1a684947cbce899 427448 rsync_3.2.7-1+deb12u1_ppc64el.deb Checksums-Sha256: 2367fd0ee8a32f141303d89e9be86c8a216a1afa8f67bc66dd11d4bdb7af2808 529492 rsync-dbgsym_3.2.7-1+deb12u1_ppc64el.deb 0ab88fae0a1526d17943a27b71117f1379d12683bc6bcf281a8dabe58efb96a4 6878 rsync_3.2.7-1+deb12u1_ppc64el-buildd.buildinfo 835ae17c618c0bdf8e83b60d770a0d923fe38d928243ad7649b6ceff0ccf02e4 427448 rsync_3.2.7-1+deb12u1_ppc64el.deb Files: 6ea9bde2fa3e8122f654a3d09e038d10 529492 debug optional rsync-dbgsym_3.2.7-1+deb12u1_ppc64el.deb f4926645824fbc71998fca3978fffe73 6878 net optional rsync_3.2.7-1+deb12u1_ppc64el-buildd.buildinfo aa08b9010414c4db7b39ac10e90f31e4 427448 net optional rsync_3.2.7-1+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5v3ycPFoB5xoBEprvMjydu+xvRMFAmd4V80ACgkQvMjydu+x vRONVw/+Nm2xhii6w7xX3OH84RC4Tl1hKHuvbsejRQJwM8KiCq8T/42cTMcpTHaQ eIV/e5lGhqYM56YmY3Hk0RXEaO6tgi4ShKiswUMRoYh5Ii+HkaqOUzSn34nNTByD V/9RGYQiRfUZIHxCbIvylKSK5GS6qzdTaGNfeXNsv4AKN8d40NQKuVzThZm0GrUl XnBHsCo9ogiMNQWDDnG97iIOMfUHkENNaYc90V4A4uZLGCCEwKbhDh30Mxr5nfjO UjOOzdT10J86s7z8Tej7O3UiHyaF/E/ysoWLQysEjMmtkeanifMyqGfuMvDMVuzK Q79oBx6ZuSrcAQSPNndQa9GjCemZaDCJ1Rdz8e44VSk4jY+Y3z4GcqZfI4gBBAIC 6QiqcaMn1OJgVTHby9U6FXyU87Djqh83PW0zQJexllmVotQvaDUffeglMyPr1hc1 uGZNBj6VYF3pNWoHQ6gv6rxKF1u4+e12YUx4mOat6TBzhLdPYyIEyHj4NJLuH3jh Vw4ospYPebMOigjfeSqDJXfjdBOQI+zhRgZ0SOyoUWcVOwzpfLkhIG1OsG5JJkKO MMbkUMiMq/4D2A4W8hwLjVFewJkUAQaCf5MjZ4yO5PMlHlUGeceVvM2UbzVBhMHS G8+eXf3Y1NpUpaCKLYybDNkxKpyqx6hlu7lZxgIEzY5wcH2swJs= =xI+N -----END PGP SIGNATURE-----