[CLSA-2025:1737463274] rsync: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-01-21 14:34:07 UTC
Description:
- CVE-2024-12088: fix path traversal vulnerability by properly verifying symbolic link destinations - CVE-2024-12085: fix issue with checksum length manipulation leading to uninitialized memory leak
Updated packages:
  • rsync-3.1.3-12.el8.tuxcare.els5.x86_64.rpm
    sha:fef8b0f21347706ffbc7cde7afb5219b953cb99e9b4390a5c564467fb8079657
  • rsync-daemon-3.1.3-12.el8.tuxcare.els5.noarch.rpm
    sha:3f3318cf0c0c3429a685569c35e9f6ed7e9f5129740e81f6cb3eac5f75b4bf9e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.