Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 569140 - <net-misc/rsync-3.1.2: unsafe destination paths for transferred files (CVE-2014-9512)
Summary: <net-misc/rsync-3.1.2: unsafe destination paths for transferred files (CVE-20...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-12-22 10:09 UTC by Lars Wendler (Polynomial-C) (RETIRED)
Modified: 2016-05-30 20:02 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2015-12-22 10:09:57 UTC
From 3.1.2 NEWS file:

  SECURITY FIXES:

    - Make sure that all transferred files use only path names from inside the
      transfer.  This makes it impossible for a malicious sender to try to make
      the receiver use an unsafe destination path for a transferred file, such
      as a just-sent symlink.


Dunno if there's a CVE for this issue.
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2015-12-27 21:15:23 UTC
Arches please test and mark stable =net-misc/rsync-3.1.2 with target KEYWORDS:

alpha amd64 arm ~arm64 hppa ia64 ~m68k ~mips ppc ppc64 ~s390 ~sh sparc x86 ~ppc-aix ~amd64-fbsd ~sparc-fbsd ~x86-fbsd ~x64-freebsd ~x86-freebsd ~hppa-hpux ~ia64-hpux ~x86-interix ~amd64-linux ~arm-linux ~ia64-linux ~x86-linux ~ppc-macos ~x64-macos ~x86-macos ~m68k-mint ~sparc-solaris ~sparc64-solaris ~x64-solaris ~x86-solaris
Comment 2 Craig Inches 2015-12-28 07:07:05 UTC
AMD64 OK
Comment 3 Agostino Sarubbo gentoo-dev 2015-12-28 08:42:16 UTC
amd64 stable
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2015-12-29 06:33:38 UTC
Stable for HPPA PPC64.
Comment 5 Andreas Schürch gentoo-dev 2016-01-06 19:55:26 UTC
x86 done
Comment 6 Markus Meier gentoo-dev 2016-01-07 20:21:48 UTC
arm stable
Comment 7 Agostino Sarubbo gentoo-dev 2016-01-09 07:11:51 UTC
sparc stable
Comment 8 Agostino Sarubbo gentoo-dev 2016-01-10 10:42:34 UTC
alpha stable
Comment 9 Agostino Sarubbo gentoo-dev 2016-01-11 09:08:36 UTC
ia64 stable
Comment 10 SpanKY gentoo-dev 2016-01-11 10:46:30 UTC
all arches done now
Comment 11 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2016-01-26 09:26:29 UTC
commit de1507df9ad772d4cf78297924c6815b83a22f7a
Author: Lars Wendler <polynomial-c@gentoo.org>
Date:   Tue Jan 26 10:25:40 2016

    net-misc/rsync: Removed vulnerable versions.
    
    Package-Manager: portage-2.2.27
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 net-misc/rsync/Manifest           |  1 -
 net-misc/rsync/rsync-3.1.1.ebuild | 75 ---------------------------------------
 2 files changed, 76 deletions(-)
Comment 12 Yury German Gentoo Infrastructure gentoo-dev 2016-02-25 07:41:46 UTC
Arches and Maintainer(s), Thank you for your work.

New GLSA Request filed.
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2016-05-30 20:02:37 UTC
This issue was resolved and addressed in
 GLSA 201605-04 at https://security.gentoo.org/glsa/201605-04
by GLSA coordinator Yury German (BlueKnight).