Security update for rsync

SUSE Security Update: Security update for rsync
Announcement ID: SUSE-SU-2016:0173-1
Rating: moderate
References: #898513 #900914 #915410 #922710
Affected Products:
  • SUSE Linux Enterprise Server 12-SP1
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Desktop 12-SP1
  • SUSE Linux Enterprise Desktop 12

  • An update that solves two vulnerabilities and has two fixes is now available.

    Description:


    This update for rsync fixes two security issues and two non-security bugs.

    The following vulnerabilities were fixed:

    - CVE-2014-8242: Checksum collisions leading to a denial of service
    (bsc#900914)
    - CVE-2014-9512: Malicious servers could send files outside of the
    transferred directory (bsc#915410)

    The following non-security bugs were fixed:

    - bsc#922710: Prevent rsyncd from spamming the log when trying to register
    SLP.
    - bsc#898513: slp support broke rsync usage.

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Server 12-SP1:
      zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-113=1
    • SUSE Linux Enterprise Server 12:
      zypper in -t patch SUSE-SLE-SERVER-12-2016-113=1
    • SUSE Linux Enterprise Desktop 12-SP1:
      zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-113=1
    • SUSE Linux Enterprise Desktop 12:
      zypper in -t patch SUSE-SLE-DESKTOP-12-2016-113=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64):
      • rsync-3.1.0-6.1
      • rsync-debuginfo-3.1.0-6.1
      • rsync-debugsource-3.1.0-6.1
    • SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64):
      • rsync-3.1.0-6.1
      • rsync-debuginfo-3.1.0-6.1
      • rsync-debugsource-3.1.0-6.1
    • SUSE Linux Enterprise Desktop 12-SP1 (x86_64):
      • rsync-3.1.0-6.1
      • rsync-debuginfo-3.1.0-6.1
      • rsync-debugsource-3.1.0-6.1
    • SUSE Linux Enterprise Desktop 12 (x86_64):
      • rsync-3.1.0-6.1
      • rsync-debuginfo-3.1.0-6.1
      • rsync-debugsource-3.1.0-6.1

    References: