[Git][security-tracker-team/security-tracker][master] Merge fixes via unstable for rsync issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jan 14 19:23:51 GMT 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2993240d by Salvatore Bonaccorso at 2025-01-14T20:23:27+01:00
Merge fixes via unstable for rsync issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,24 +7,24 @@ CVE-2024-50349
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/4
NOTE: Fixed by: https://github.com/git/git/commit/7725b8100ffbbff2750ee4d61a0fcc1f53a086e8 (v2.40.4)
CVE-2024-12747
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
CVE-2024-12088
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
NOTE: https://github.com/RsyncProject/rsync/commit/407c71c7ce562137230e8ba19149c81ccc47c387
CVE-2024-12087
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
CVE-2024-12086
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
CVE-2024-12085
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
NOTE: https://github.com/RsyncProject/rsync/commit/589b0691e59f761ccb05ddb8e1124991440db2c7
CVE-2024-12084
- - rsync <unfixed>
+ - rsync 3.3.0+ds1-3
[bullseye] - rsync <not-affected> (Vulnerable code introduced later)
NOTE: Fixed by: https://git.samba.org/?p=rsync.git;a=commit;h=0902b52f6687b1f7952422080d50b93108742e53
NOTE: https://www.openwall.com/lists/oss-security/2025/01/14/3
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2993240d6165454bb2b276571c5a14fac982e375
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2993240d6165454bb2b276571c5a14fac982e375
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250114/e23f3ae7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list