Summary: | <net-misc/rsync-3.2.3-r5: improper TLS validation in rsync-ssl script (CVE-2020-14387) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | base-system |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1875549 | ||
See Also: | https://github.com/gentoo/gentoo/pull/22981 | ||
Whiteboard: | A3 [glsa? cleanup] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 827218 | ||
Bug Blocks: |
Description
Sam James
![]() ![]() ![]() ![]() Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=029532544d5edfe5fc70413a827831932e3c0b21 commit 029532544d5edfe5fc70413a827831932e3c0b21 Author: Varsha Teratipally <teratipally@google.com> AuthorDate: 2021-11-17 17:30:16 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2021-11-18 02:30:46 +0000 net-misc/rsync: fix CVE-2020-14387 Bug: https://bugs.gentoo.org/792576 Signed-off-by: Varsha Teratipally <teratipally@google.com> Closes: https://github.com/gentoo/gentoo/pull/22981 Signed-off-by: Sam James <sam@gentoo.org> .../files/rsync-3.2.3-verify-certificate.patch | 26 +++++ net-misc/rsync/rsync-3.2.3-r5.ebuild | 124 +++++++++++++++++++++ 2 files changed, 150 insertions(+) Please cleanup |