Release Info

Advisory: CLSA-2022:1662658118

OS: Ubuntu 16.04 ELS

Public date: 2022-09-08 00:00:00

Project: rsync

Version: 3.1.1-3ubuntu1.3+tuxcare.els4

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2022-1662658118.html

Changelog

* SECURITY UPDATE: arbitrary file write vulnerability via malicious rsync server (MITM attack), refactoring - debian/patches/CVE-2022-29154-0.patch: prepare for CVE-2022-29154 patch - debian/patches/CVE-2022-29154-1.patch: add extra file-list safety checks - CVE-2022-29154

Update

Update command: apt-get update apt-get --only-upgrade install rsync*

Packages list

rsync_3.1.1-3ubuntu1.3+tuxcare.els4_amd64.deb

CVEs

CVE-2022-29154