SUSE-SU-2016:0173-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0173-1
SUSE-SU-2016:0173-1
Summary: Security update for rsync
Details: This update for rsync fixes two security issues and two non-security bugs. The following vulnerabilities were fixed: - CVE-2014-8242: Checksum collisions leading to a denial of service (bsc#900914) - CVE-2014-9512: Malicious servers could send files outside of the transferred directory (bsc#915410) The following non-security bugs were fixed: - bsc#922710: Prevent rsyncd from spamming the log when trying to register SLP. - bsc#898513: slp support broke rsync usage.
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160173-1/, https://bugzilla.suse.com/898513, https://bugzilla.suse.com/900914, https://bugzilla.suse.com/915410, https://bugzilla.suse.com/922710, https://www.suse.com/security/cve/CVE-2014-8242, https://www.suse.com/security/cve/CVE-2014-9512
Affected packages
Package
Name: rsync
Purl: pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
