Post Syndicated from jzb original https://lwn.net/Articles/1088759/
Version
3.5.0 of rsync has been released with a huge
number of security fixes:
This release fixes 33 security issues found during a focused audit of
rsync’s path handling and daemon protocol, a companion daemon-protocol
fuzzing pass, and reports from external researchers -- plus several
robustness hardenings. CVE IDs were assigned by VulnCheck (CNA); the
precise “introduced in” version ranges accompany each advisory, and
many are much narrower than “everything before 3.5.0”. Every fix ships
with a regression test in the test suite that fails on the unfixed
tree.