RE: new release 3.4.0 - critical security release

"Randall S. Becker via rsync" <[email protected]> Tue, 14 Jan 2025 15:16:30 -0500
Newsgroups gmane.network.rsync.general,gmane.network.rsync.announce
Organization Nexbridge Inc.
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============4421505467820405656==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0427_01DB6697.4DC3E420"
Content-Language: en-ca

This is a multipart message in MIME format.

------=_NextPart_000_0427_01DB6697.4DC3E420
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

A new dependency was added since 3.3, alloca(), which is not portable. =
Is there a way around this?

Thanks,

Randall

=20

From: rsync <[email protected]> On Behalf Of rsync.project =
via rsync
Sent: January 14, 2025 2:49 PM
To: [email protected]
Cc: [email protected]
Subject: new release 3.4.0 - critical security release

=20

We have just released version 3.4.0 of rsync. This release fixes 6 =
security vulnerabilities found by two groups of security researchers.

=20

You can find the new release links here:

=20

 - https://rsync.samba.org/

 - https://download.samba.org/pub/rsync/src/

=20

For details on the vulnerabilities please see this CERT advisory:

=20

https://kb.cert.org/vuls/id/952657

=20

The various distros should be doing security releases today

Many thanks to Simon Scannell, Pedro Gallegos, and Jasiel Spelman at =
Google Cloud Vulnerability Research and Aleksei Gorban (Loqpa) for =
discovering these vulnerabilities and working with the rsync project to =
develop and test fixes.

=20

Also many thanks to Wayne Davison for assisting with the release process =
as this is the first release I've done since 2002 when Wayne took over =
as the rsync maintainer.

=20

Andrew Tridgell

rsync maintainer (again!)

=20

=20


------=_NextPart_000_0427_01DB6697.4DC3E420
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:11.0pt;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-CA link=3Dblue =
vlink=3Dpurple style=3D'word-wrap:break-word'><div =
class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;mso-fareast-language:EN-US'>A new dependency =
was added since 3.3, alloca(), which is not portable. Is there a way =
around this?<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;mso-fareast-language:EN-US'>Thanks,<o:p></o:p><=
/span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;mso-fareast-language:EN-US'>Randall<o:p></o:p><=
/span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></=
span></p><div style=3D'border:none;border-left:solid blue =
1.5pt;padding:0cm 0cm 0cm 4.0pt'><div><div =
style=3D'border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm'><p class=3DMsoNormal><b><span lang=3DEN-US =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span><=
/b><span lang=3DEN-US =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'> rsync =
&lt;[email protected]&gt; <b>On Behalf Of </b>rsync.project =
via rsync<br><b>Sent:</b> January 14, 2025 2:49 PM<br><b>To:</b> =
[email protected]<br><b>Cc:</b> =
[email protected]<br><b>Subject:</b> new release 3.4.0 - critical =
security release<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>We have =
just released version 3.4.0 of rsync. This release fixes 6 security =
vulnerabilities found by two groups of security =
researchers.<o:p></o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>You can find the new release links =
here:<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>&nbsp;- <a =
href=3D"https://rsync.samba.org/">https://rsync.samba.org/</a><o:p></o:p>=
</p></div><div><p class=3DMsoNormal>&nbsp;-&nbsp;<a =
href=3D"https://download.samba.org/pub/rsync/src/">https://download.samba=
.org/pub/rsync/src/</a><o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>For =
details on the vulnerabilities please see this CERT =
advisory:<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><a =
href=3D"https://kb.cert.org/vuls/id/952657">https://kb.cert.org/vuls/id/9=
52657</a><o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>The various distros should be doing security releases =
today<o:p></o:p></p></div><div><p class=3DMsoNormal>Many thanks to Simon =
Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud =
Vulnerability Research and Aleksei Gorban (Loqpa) for discovering these =
vulnerabilities and working with the rsync project to develop and test =
fixes.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Also many thanks to Wayne Davison for assisting with =
the release process as this is the first release I've done since 2002 =
when Wayne took over as the rsync =
maintainer.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Andrew Tridgell<o:p></o:p></p></div><div><p =
class=3DMsoNormal>rsync maintainer (again!)<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></div></div></div></bo=
dy></html>
------=_NextPart_000_0427_01DB6697.4DC3E420--



--===============4421505467820405656==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
Please use reply-all for most replies to avoid omitting the mailing list.
To unsubscribe or change options: https://lists.samba.org/mailman/listinfo/rsync
Before posting, read: http://www.catb.org/~esr/faqs/smart-questions.html

--===============4421505467820405656==--