Packages
- rsync - fast, versatile, remote (and local) file-copying tool
Details
Koen van Hove discovered that the rsync client incorrectly validated
filenames returned by servers. If a user or automated system were tricked
into connecting to a malicious server, a remote attacker could use this
issue to write arbitrary files, and possibly escalate privileges.
Koen van Hove discovered that the rsync client incorrectly validated
filenames returned by servers. If a user or automated system were tricked
into connecting to a malicious server, a remote attacker could use this
issue to write arbitrary files, and possibly escalate privileges.
Update instructions
On Ubuntu 22.04 LTS and Ubuntu 22.10, this update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
22.10 kinetic | rsync – 3.2.7-0ubuntu0.22.10.1 | ||
22.04 jammy | rsync – 3.2.7-0ubuntu0.22.04.2 | ||
20.04 focal | rsync – 3.1.3-8ubuntu0.5 | ||
18.04 bionic | rsync – 3.1.2-2.1ubuntu1.6 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.