rsync is NOT vulnerable to the latest zlib security problem

Wayne Davison <[email protected]> Mon, 11 Jul 2005 10:13:34 -0700
Newsgroups gmane.network.rsync.general,gmane.network.rsync.announce
Message-ID <[email protected]>
--===============0188560394==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="Nq2Wo0NMKNjxTN9z"
Content-Disposition: inline


--Nq2Wo0NMKNjxTN9z
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

The zlib folks have clarified that version 1.1.4 is not vulnerable to
the latest zlib security problem, so all released versions of rsync are
not affected by the most recent security problem that was found in
version 1.2.2 (and also affects 1.2.1).  So, there is now no rush to
release version 2.6.6 of rsync.  Instead, it can act as a trial version
to ensure that upgrading the zlib version is not going to cause any
problems, and I will allow a little more in the way of features to be
added to rsync before releasing the final 2.6.6.

I apologize for the confusion, but I was playing it safe in case rsync
was affected by this zlib vulnerability.

..wayne..

--Nq2Wo0NMKNjxTN9z
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFC0qi+bIWfsUuWqMURAscZAJwKZKj9HkN1vVCoiqBjrHvlWEznDACdH5y9
aYqOrQV6GavblmaBSi492Ug=
=XhRx
-----END PGP SIGNATURE-----

--Nq2Wo0NMKNjxTN9z--

--===============0188560394==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
To unsubscribe or change options: https://lists.samba.org/mailman/listinfo/rsync
Before posting, read: http://www.catb.org/~esr/faqs/smart-questions.html
--===============0188560394==--