USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacker could exploit this
to write files outside the intended directory. (CVE-2024-12087)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
failed to verify symbolic link destinations for some settings. An
attacker could exploit this for path traversal attacks. (CVE-2024-12088)
Aleksei Gorban discovered a race condition in rsync’s handling of
symbolic links. An attacker could use this to access sensitive
information or escalate privileges. (CVE-2024-12747)
More Stories
tigervnc-1.15.0-2.fc42
FEDORA-2025-ef7fb833f2 Packages in this update: tigervnc-1.15.0-2.fc42 Update description: Fixes for xorg-x11-server CVEs. Read More
tigervnc-1.15.0-2.fc40
FEDORA-2025-a87bc329fe Packages in this update: tigervnc-1.15.0-2.fc40 Update description: Fixes for xorg-x11-server CVEs. Read More
USN-7312-1: openNDS vulnerability
It was discovered that openNDS did not correctly handle certain memory operations. An attacker could possibly use this issue to...
nextcloud-29.0.12-2.el9
FEDORA-EPEL-2025-b1460ceecd Packages in this update: nextcloud-29.0.12-2.el9 Update description: 29.0.12 release RHBZ#2324262 Read More
nextcloud-31.0.0-1.fc42
FEDORA-2025-31e079a8a8 Packages in this update: nextcloud-31.0.0-1.fc42 Update description: 31.0.0 release RHBZ#2324262 RHBZ#2336564 Read More
nextcloud-31.0.0-1.fc43
FEDORA-2025-beab5b2e5e Packages in this update: nextcloud-31.0.0-1.fc43 Update description: Automatic update for nextcloud-31.0.0-1.fc43. Changelog * Sun Mar 2 2025 Andrew Bauer...