-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 18 Dec 2024 17:11:25 +0100 Source: rsync Binary: rsync rsync-dbgsym Architecture: armhf Version: 3.2.7-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Salvatore Bonaccorso Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.2.7-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Some checksum buffer fixes. (CVE-2024-12084) * Another cast when multiplying integers. (CVE-2024-12084) * prevent information leak off the stack (CVE-2024-12085) * refuse fuzzy options when fuzzy not selected (CVE-2024-12086) * added secure_relative_open() (CVE-2024-12086) * receiver: use secure_relative_open() for basis file (CVE-2024-12086) * disallow ../ elements in relpath for secure_relative_open (CVE-2024-12086) * Refuse a duplicate dirlist. (CVE-2024-12087) * range check dir_ndx before use (CVE-2024-12087) * make --safe-links stricter (CVE-2024-12088) * fixed symlink race condition in sender (CVE-2024-12747) * raise protocol version to 32 Checksums-Sha1: a614305bcbae34e2060ea76c57dd084fecc22986 514816 rsync-dbgsym_3.2.7-1+deb12u1_armhf.deb d13e7c913ce25702807bbfe67c0201c631e5ec69 6741 rsync_3.2.7-1+deb12u1_armhf-buildd.buildinfo 785673cf951ac318a6ad60e5f5148e71ddb461fe 395480 rsync_3.2.7-1+deb12u1_armhf.deb Checksums-Sha256: ce486449b337662c6f6f22a4324d512c1097d3ce85536546e06dc86cdc27764f 514816 rsync-dbgsym_3.2.7-1+deb12u1_armhf.deb e68a10a55a660e0cfc51dbc8af3c32597be732f936de80ff56e2c6dd0ee34ffd 6741 rsync_3.2.7-1+deb12u1_armhf-buildd.buildinfo 01582c875499886b0d28a074c833ad016452617c93dec9be3a1a7a48da2cf28b 395480 rsync_3.2.7-1+deb12u1_armhf.deb Files: 888485bf4d11457d9b55e3a3a592cc4a 514816 debug optional rsync-dbgsym_3.2.7-1+deb12u1_armhf.deb 6a6aa6f838e4edf2751d12f13bc31dff 6741 net optional rsync_3.2.7-1+deb12u1_armhf-buildd.buildinfo a48d498dc8fd79bf397e83d94a85e094 395480 net optional rsync_3.2.7-1+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmd4WBEACgkQ4CwlMGxH D8WNpBAAsBuvr5j3CRfAfZiVNZ1o9xXBJNk17AvMCLOzHPoAmnkgdf452QLWNx1N 8276Z7UgOpg4GfbEVJ20NjEByrxnggrqhcsQi8CmPWTeTiTaRkaKdxCXzSwtxAcI aoDX8VjhpSl6BYMOOvKzuPZ/Eo9vqi+Om16ytltkIYCv+22ps9kuZVKpSXxSRhYf zvqT2C6yXgR//FgunUUW1EsCRr4z3wrlez9BD/KLAe2xlt9MqOwn58ABFGfopp9U 7YrrHqOtFSFiOl7VDnWcD6LHKF90MTxPaVgSSZAkVsQVBWsrCyAFkOlZCEUYN3Zm 31Yd/4pkqmB5TsHw31bxwpsB2wsFt2uJ6JyXMR5fXHPti/S3KLZFsYeunzmngQ8H cQTMrfVfXpbYFIqbE1LldlRg3c4izIR6IVApP3fS8BA/uT5CsD9mWGo2G6WmDkm4 6kCSMFuJ2FjFg2qNp18lfO54V5aow+2KpkdEh1oUML3JPeSoNfZje9vZiKHklpD+ DaI7ikjPQIiQnSV+Vcqk1htmIKbEnmYbeTOqnSPGRf/7uWaZyWa/OIEL9QLlX0py hsxbbJRNRsLSxUi5wL593ij37oNsq52Yjl94GuYvp4dKq5LeoEDHpBxgIQZjfM9c n/EQsOhLeyjuTwpDdgq+Djgc1JFuGWd22Cliei/6zjF0GKmQQJ0= =/aC/ -----END PGP SIGNATURE-----