[CLSA-2025:1738632106] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2025-02-04 01:21:52 UTC
Description:
- CVE-2024-12086: fix infoleak when connect to malicious server - CVE-2024-12088: properly verify if a symbolic link destination contains another symbolic link within it when using the '--safe-links' option
Updated packages:
  • rsync-3.1.3-19.el8.1.tuxcare.els4.x86_64.rpm
    sha:ac9e36a3d437d663f1f21144596010562cac8177c691248b1cf8bfe609c91e56
  • rsync-daemon-3.1.3-19.el8.1.tuxcare.els4.noarch.rpm
    sha:a0151add7fb4d69901dc70ce8f8809687ce09e356aeb5a18b2a13f9cad02324c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.