Format: 1.8 Date: Thu, 18 Jan 2018 16:43:26 -0300 Source: rsync Binary: rsync Architecture: i386 Version: 3.0.9-1ubuntu1.3 Distribution: precise Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Leonidas S. Barbosa Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.0.9-1ubuntu1.3) precise-security; urgency=medium . * SECURITY UPDATE: receive_xattr function does not check for '\0' character allowing denial of service attacks - debian/patches/CVE-2017-16548.patch: enforce trailing \0 when receiving xattr values in xattrs.c. - CVE-2017-16548 * SECURITY UPDATE: Allows remote attacker to bypass argument - debian/patches/CVE-2018-5764.patch: Ignore --protect-args when already sent by client in options.c. - CVE-2018-5764 Checksums-Sha1: 040c723611888fa4ccb7eecaa3e30f05b57fa79e 299646 rsync_3.0.9-1ubuntu1.3_i386.deb Checksums-Sha256: f29b5e31fdb682d9a64fc7e5bf1b8a6907414ff17a9c290cdf48327878f570b3 299646 rsync_3.0.9-1ubuntu1.3_i386.deb Files: 62fdb7a1209156569fb85135186e3726 299646 net optional rsync_3.0.9-1ubuntu1.3_i386.deb Original-Maintainer: Paul Slootman