Bug#621866: rsync: CVE-2011-1097 DoS and possibly code execution on client side

2012-08-21 Thread Jonathan Wiltshire
Package: rsync Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.6) -

Bug#621866: rsync: CVE-2011-1097 DoS and possibly code execution on client side

2011-04-09 Thread Nico Golde
Package: rsync Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities Exposures) id was published for rsync. CVE-2011-1097[0]: | rsync 3.x before 3.0.8, when certain recursion, deletion, and | ownership options are used, allows remote rsync servers to cause a |