New ftpsync version 20171017 (security update)
Bastian Blank <[email protected]>
| Newsgroups | gmane.linux.debian.user.mirrors |
|---|---|
| Message-ID | <[email protected]> |
Hello mirror operators We released ftpsync 20171017 today. This is a security update, it fixes CVE-2017-8805. rsync was called without --safe-links. This allowed the creating of symlinks to files outside of the mirrored tree. If the mirror also provides access via HTTP, the server will usually follow symlinks and allow access to arbitrary files or directories. Other notable changes are: * We added support for rsync-over-SSH, * We tried to really add documentation that is not example configs. Several parts are still missing, but we are getting there. You can find the new ftpsync version on a Debian mirror near you. Regards, Bastian -- Suffocating together ... would create heroic camaraderie. -- Khan Noonian Singh, "Space Seed", stardate 3142.8
signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEER3HMN63jdS1rqjxLbZOIhYpp/lEFAlnmLbUACgkQbZOIhYpp /lHh2wf/XYkfk1wLn8J7J8Lb/lFw0DBJ+hoWjJonD9hpEg42UXzBNPLRlbSyLmoC f4wgfQL5ZtIN4tSmdEWlt4LkHtEVQAv50lWANua2D/YnHuA7UrKIyHh8Kuph79iF DxfjQiPeURsHWmwBZELByUAl33wQWXozQ3BQW67uaIlI5U4s5bOGXXUzHiSx8Zjb RL5n7cwIpYsgrTc+QF6GF5n7ILeN4P4PWYjaWidE+3WZRTz65jPgHSXlCSNB0Q6D EcpLvuH17AnnAzQ7FdWIaPpkKx5qFHOhS9Ohf8D/2qFcbbZHVSaM8saVhVvzbG3P 4ryj/KUjY3MRFJv6RXfpBuBdaLBvnw== =tmYt -----END PGP SIGNATURE-----