Slackware alert: rsync update fixes security problems

Posted by dave on Mar 11, 2002 2:25 PM EDT
Mailing list
Mail this story
Print this story

New rsync packages are available to fix security problems.

New rsync packages are available to fix security problems.

Here's the information from the Slackware 8.0 ChangeLog:

---------------------------- Mon Mar 11 15:09:26 PST 2002 patches/packages/rsync.tgz: Upgraded to rsync-2.5.3. This fixes two security problems:

* Make sure that supplementary groups are removed from a server process after changing uid and gid. (Ethan Benson) (Debian bug #132272, CVE CAN-2002-0080)

* Fix zlib double-free bug. (Owen Taylor, Mark J Cox) (CVE CAN-2002-0059)

(* Security fix *) ----------------------------

We recommend that sites providing external rsync access upgrade to the fixed rsync package as soon as possible.

WHERE TO FIND THE NEW PACKAGE: ------------------------------ Updated rsync package for Slackware 8.0:

Updated rsync package for Slackware 7.1:

MD5 SIGNATURE: --------------

Here are the md5sums for the packages:

Slackware 8.0: e88390bae124be2af4b707ad3fbfc791 rsync.tgz

Slackware 7.1: 959b82dd4fbb84da564b2ce18eb56afc rsync.tgz

INSTALLATION INSTRUCTIONS: --------------------------

Simply upgrade as root:

# upgradepkg rsync.tgz

Remember, it's also a good idea to backup configuration files before upgrading packages.

- Slackware Linux Security Team

+------------------------------------------------------------------------+ | HOW TO REMOVE YOURSELF FROM THIS MAILING LIST: | +------------------------------------------------------------------------+ | Send an email to with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back. Follow the instructions to | | complete the unsubscription. Do not reply to this message to | | unsubscribe! | +------------------------------------------------------------------------+

» Read more about: Story Type: Security; Groups: Slackware

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.