rsync-3.1.3-19.el8

エラータID: AXSA:2022-4191:08

Release date: 
Monday, November 28, 2022 - 10:44
Subject: 
rsync-3.1.3-19.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

* zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field (CVE-2022-37434)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.7 Release Notes linked from the References section.

CVE-2022-37434
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rsync-3.1.3-19.el8.src.rpm
    MD5: a2c3874a2e2bc79c89b6afc5d4a85241
    SHA-256: d0692af21e119d5b00561d4e917ec3ebdd8b7bc839c6d7ae6cd68ab210c7774d
    Size: 1.09 MB

Asianux Server 8 for x86_64
  1. rsync-3.1.3-19.el8.x86_64.rpm
    MD5: caa8af84ff81b7147db72b6ec3ee751a
    SHA-256: eaf44223aa4369714da96ffd259918dde06a12a38fe1e9f0ebf054e2e15ee5fb
    Size: 408.99 kB
  2. rsync-daemon-3.1.3-19.el8.noarch.rpm
    MD5: 01a0aa409073dbf5e83fd1d5fdceebb8
    SHA-256: 9517f092cd6169a6e7059678baae9bd6cb4c25b19647a7d92d9049eac012b1b4
    Size: 43.11 kB