FS#69051 - [rsync] [Security] man-in-the-middle (CVE-2020-14387)
Attached to Project:
Arch Linux
Opened by Jonas Witschel (diabonas) - Monday, 21 December 2020, 12:48 GMT
Last edited by Christian Hesse (eworm) - Monday, 21 December 2020, 20:38 GMT
Opened by Jonas Witschel (diabonas) - Monday, 21 December 2020, 12:48 GMT
Last edited by Christian Hesse (eworm) - Monday, 21 December 2020, 20:38 GMT
|
Details
Summary
======= The package rsync is vulnerable to man-in-the-middle via CVE-2020-14387. Guidance ======== Applying the patch linked below fixes the issue and will be part of the yet unreleased version 3.2.4. References ========== https://security.archlinux.org/AVG-1374 https://bugzilla.redhat.com/show_bug.cgi?id=1875549 https://git.samba.org/?p=rsync.git;a=commitdiff;h=c3f7414c450faaf6a8281cc4a4403529aeb7d859 |
This task depends upon
Closed by Christian Hesse (eworm)
Monday, 21 December 2020, 20:38 GMT
Reason for closing: Fixed
Additional comments about closing: rsync 3.2.3-2
Monday, 21 December 2020, 20:38 GMT
Reason for closing: Fixed
Additional comments about closing: rsync 3.2.3-2