
Package "rsync"

Name: rsync


fast, versatile, remote (and local) file-copying tool

Latest version: 3.2.7-0ubuntu0.22.04.4
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://rsync.samba.org/


Download "rsync"

Other versions of "rsync" in Jammy

Repository Area Version
base main 3.2.3-8ubuntu3
security main 3.2.7-0ubuntu0.22.04.4


Version: 3.2.7-0ubuntu0.22.04.4 2025-01-16 23:06:49 UTC

  rsync (3.2.7-0ubuntu0.22.04.4) jammy-security; urgency=medium

  * SECURITY REGRESSION: flag collision (LP: #2095004)
    - d/p/fix_flag_got_dir_flist_collision.patch: change the flag bit to 13

 -- Sudhakar Verma <email address hidden> Thu, 16 Jan 2025 15:25:20 +0530

Source diff to previous version
2095004 Internal hashtable error: illegal key supplied!

Version: 3.2.7-0ubuntu0.22.04.3 2025-01-15 01:06:51 UTC

  rsync (3.2.7-0ubuntu0.22.04.3) jammy-security; urgency=medium

  * SECURITY UPDATE: safe links bypass vulnerability
    - d/p/CVE-2024-12088/0001-make-safe-links-stricter.patch: reject
      links where a "../" component is included in the destination
    - CVE-2024-12088
  * SECURITY UPDATE: arbitrary file write via symbolic links
    - d/p/CVE-2024-12087/0001-Refuse-a-duplicate-dirlist.patch: refuse
      malicious duplicate flist for dir
    - d/p/CVE-2024-12087/0002-range-check-dir_ndx-before-use.patch: refuse
      invalid dir_ndx
    - CVE-2024-12087
  * SECURITY UPDATE: arbitrary client file leak
    - d/p/CVE-2024-12086/0001-refuse-fuzzy-options-when-fuzzy-not-selected.patch:
      refuse fuzzy options when not selected
    - d/p/CVE-2024-12086/0002-added-secure_relative_open.patch: safe
      implementation to open a file relative to a base directory
    - d/p/CVE-2024-12086/0003-receiver-use-secure_relative_open-for-basis-file.patch:
      ensure secure file access for basis file
    - d/p/CVE-2024-12086/0004-disallow-.-elements-in-relpath-for-secure_relative_o.patch:
      disallow "../" in relative path
    - CVE-2024-12086
  * SECURITY UPDATE: information leak via uninitialized stack contents
    - d/p/CVE-2024-12085/0001-prevent-information-leak-off-the-stack.patch:
      prevent information leak by zeroing
    - CVE-2024-12085
  * SECURITY UPDATE: heap buffer overflow in checksum parsing
    - d/p/CVE-2024-12084/0001-Some-checksum-buffer-fixes.patch: fix
      checksum buffer issues, better length check
    - d/p/CVE-2024-12084/0002-Another-cast-when-multiplying-integers.patch:
      fix multiplying size by a better cast
    - CVE-2024-12084
  * SECURITY UPDATE: symlink race condition
    - d/p/CVE-2024-12747/0001-fixed-symlink-race-condition-in-sender.patch:
      do_open_checklinks to prevent symlink race
    - CVE-2024-12747

 -- Sudhakar Verma <email address hidden> Mon, 13 Jan 2025 16:36:53 +0530

Source diff to previous version
CVE-2024-12088 A flaw was found in rsync. When using the `--safe-links` option, rsync ...
CVE-2024-12087 A path traversal vulnerability exists in rsync. It stems from behavior ...
CVE-2024-12086 A flaw was found in rsync. It could allow a server to enumerate the co ...
CVE-2024-12085 A flaw was found in the rsync daemon which could be triggered when rsy ...
CVE-2024-12747 A flaw was found in rsync. This vulnerability arises from a race condi ...

Version: 3.2.7-0ubuntu0.22.04.2 2023-03-06 15:06:57 UTC

  rsync (3.2.7-0ubuntu0.22.04.2) jammy-security; urgency=medium

  * SECURITY UPDATE: arbitrary file write via malicious remote servers
    - Updated to 3.2.7 to fix security issue and multiple regressions
      caused by the original security fixes.
    - debian/patches: Added two additional upstream patches:
      + trust_the_sender_on_a_local_transfer.patch
      + avoid_quoting_of_tilde_when_its_a_destination_arg.patch
    - Removed patches no longer needed with 3.2.7:
      + CVE-2020-14387.patch, fix_ftcbfs_configure.patch,
        fix_delay_updates.patch, copy-devices.diff,
        manpage_upstream_fixes.patch, fix_mkpath.patch,
        fix_sparse_inplace.patch, update_rrsync_options.patch,
    - debian/control, debian/rules, debian/rsync.install,
      debian/rsync.links: ship new python-based rrsync.
    - debian/rsync.install: cull_options has been renamed to cull-options.
    - CVE-2022-29154

 -- Marc Deslauriers <email address hidden> Mon, 27 Feb 2023 14:36:14 -0500

Source diff to previous version
CVE-2020-14387 A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthentic
CVE-2022-29154 An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peer

Version: 3.2.3-8ubuntu3.1 2022-11-21 11:07:18 UTC

  rsync (3.2.3-8ubuntu3.1) jammy; urgency=medium

  * d/p/avoid_spurious_is_newer_messages_with_update.patch: New patch from
    upstream (LP: #1965076)

 -- Simon Deziel <email address hidden> Tue, 11 Oct 2022 22:37:36 +0000

1965076 rsync --update incorrectly reports file \

About   -   Send Feedback to @ubuntu_updates