Format: 1.8 Date: Wed, 06 Dec 2017 11:36:31 -0300 Source: rsync Binary: rsync Architecture: amd64 Version: 3.1.0-2ubuntu0.3 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Leonidas S. Barbosa Description: rsync - fast, versatile, remote (and local) file-copying tool Changes: rsync (3.1.0-2ubuntu0.3) trusty-security; urgency=medium . * SECURITY UPDATE: bypass intended access restrictions - debian/patches/CVE-2017-17433.patch: check fname in recv_files sooner in receiver.c. - CVE-2017-17433 * SECURITY UPDATE: not check for fnamecmp filenames and does not apply sanitize_paths - debian/patches/CVE-2017-17434-part1.patch: check daemon filter against fnamecmp in receiver.c. - debian/patches/CVE-2017-17434-part2.patch: sanitize xname in rsync.c. - CVE-2017-17434 Checksums-Sha1: c3d67a6620a2fbd2b239fe8c9d7ac2b7e0c14467 283876 rsync_3.1.0-2ubuntu0.3_amd64.deb Checksums-Sha256: 1969bacdf6c3e5fd7429ab3571b5cdbdc5b1e9c5b29a89ea271ec802b669ad98 283876 rsync_3.1.0-2ubuntu0.3_amd64.deb Files: 18090b57007c547f2ad0f3115c394a2f 283876 net optional rsync_3.1.0-2ubuntu0.3_amd64.deb Original-Maintainer: Paul Slootman