Accepted: rsync 2.6.9-5.1ubuntu1 (source)

Michael Vogt michael.vogt at ubuntu.com
Thu Dec 6 11:40:18 GMT 2007


Accepted:
 OK: rsync_2.6.9.orig.tar.gz
 OK: rsync_2.6.9-5.1ubuntu1.diff.gz
 OK: rsync_2.6.9-5.1ubuntu1.dsc
     -> Component: main Section: net

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu, 06 Dec 2007 12:34:46 +0100
Source: rsync
Binary: rsync
Architecture: source
Version: 2.6.9-5.1ubuntu1
Distribution: hardy
Urgency: high
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
Description: 
 rsync      - fast remote file copy program (like rcp)
Closes: 453652
Changes: 
 rsync (2.6.9-5.1ubuntu1) hardy; urgency=low
 .
   * Merge from debian unstable, remaining changes:
     - Remove stop links from rc0 and rc6
       (and use update-rc.d multiuser instead of defaults)
     - maintainer field changed
     - depend on sysv-rc
 .
 rsync (2.6.9-5.1) unstable; urgency=high
 .
   * Non-maintainer upload by testing-security team.
   * This update addresses the following security issues (Closes: #453652):
     - When "use chroot" option is disabled, a programming error
       can be exploited by a user to trick rsync into creating a
       symlink that points outside the module's hierarchy.
     - A programming error within the "exclude", "exclude from" and "filter"
       options can be exploited via a symlink attack to gain access
       to hidden files if the filename is known.
Files: 
 9b23f2f3139523ea5eab63ea44a0e04c 658 net optional rsync_2.6.9-5.1ubuntu1.dsc
 bd2651b86df3739efa2e03ee4d31cd8f 43801 net optional rsync_2.6.9-5.1ubuntu1.diff.gz
Original-Maintainer: Paul Slootman <paul at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHV99IliSD4VZixzQRAk6YAJsEagQuD+1scWMWZwjzcEuNZ1kbLQCeNH6a
vGhN2NncO5ltu3D7kGoPQIY=
=1use
-----END PGP SIGNATURE-----





More information about the Hardy-changes mailing list