Rsync as the widely-used, open-source remote sync software for synchronizing files and directories across networks is out today with a very important update. Rsync 3.5 released today with 33 security fixes. The Rsync NEWS update describes it as an "extraordinary release" due to the volume of security issues. The 33 security issues stem from a focused audit of the path handling and daemon protocol and related code. The Rsync 3.5 security fixes include arbitrary file read/transfer-shaping via symlinked operator-supplied input files, arbitrary file write/privilege escalation via symlinked operator-supplied output paths, and a number of high CVEs. Simply put, there are a lot of important security updates for Rsync 3.5. The NEWS update outlines all of the important security fixes. Rsync 3.5 for those building on their own can find the latest sources via Samba.org.
Rsync 3.5 Released As "Extraordinary" Update To Fix 33 Security Issues
Full Article
Original Source
Read the full article at Phoronix →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.