[Touch-packages] [Bug 1531061] Re: Rsync path spoofing attack vulnerability

2016-08-25 Thread Rolf Leggewie
This was indeed fixed in xenial and trusty already. Thanks for reporting. rsync (3.1.1-3ubuntu1) xenial; urgency=medium * SECURITY UPDATE: incomplete fix for rsync path spoofing attack - debian/patches/CVE-2014-9512-2.diff: add parent-dir validation for --no-inc-recurse too in

[Touch-packages] [Bug 1531061] Re: Rsync path spoofing attack vulnerability

2016-01-05 Thread Seth Arnold
Looks like this is http://people.canonical.com/~ubuntu- security/cve/2014/CVE-2014-9512.html ** Information type changed from Private Security to Public Security ** Changed in: rsync (Ubuntu) Status: New => Confirmed ** CVE added: http://www.cve.mitre.org/cgi-