From 88ebe56470c37b02a044e1091cad6b2df0f3be8f Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 11 May 2018 16:02:49 +0100 Subject: gentoo resync : 11.05.2018 --- metadata/glsa/Manifest | 30 ++++++++++++------------ metadata/glsa/Manifest.files.gz | Bin 423449 -> 423609 bytes metadata/glsa/glsa-201805-04.xml | 48 +++++++++++++++++++++++++++++++++++++++ metadata/glsa/timestamp.chk | 2 +- metadata/glsa/timestamp.commit | 2 +- 5 files changed, 65 insertions(+), 17 deletions(-) create mode 100644 metadata/glsa/glsa-201805-04.xml (limited to 'metadata/glsa') diff --git a/metadata/glsa/Manifest b/metadata/glsa/Manifest index 6726bb5a02b0..0ed1024c0d68 100644 --- a/metadata/glsa/Manifest +++ b/metadata/glsa/Manifest @@ -1,23 +1,23 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 423449 BLAKE2B 490b3d49b1771ae622d89196faa36c2d3d274e6d765ed1a321c6f9c87e1eb16d0203672388185976cbe2316abc3aecaee60e0fd848bbf8c908b233ead62e69f8 SHA512 dbad8dc00d617765448bf9e5b166abdc6106321cb88ddbcbdeb94b96a977fd0d73a2a2806812a142d60c061d18208f0f31b4d01f9b25406ea237913f539f54fd -TIMESTAMP 2018-05-08T12:08:26Z +MANIFEST Manifest.files.gz 423609 BLAKE2B cbd920553b52bd805c115c763e4d6e2ee3d453ad1d6dfc315556c7a37a40f6e92d25437ae0c4238712e49a25ff5de88a4a56f425e3de6b9710d55daa2faef491 SHA512 3ac6837ed015c4c2f983100055b2867a7affaa1fd0de409b6c572144638db29f44f2af6b02450bb12cf8d1d79d3f90f56519fcc92e5b499d612f1c4c59fb4481 +TIMESTAMP 2018-05-11T14:08:26Z -----BEGIN PGP SIGNATURE----- -iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlrxkzpfFIAAAAAALgAo +iQKTBAEBCgB9FiEE4dartjv8+0ugL98c7FkO6skYklAFAlr1o9pfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEUx RDZBQkI2M0JGQ0ZCNEJBMDJGREYxQ0VDNTkwRUVBQzkxODkyNTAACgkQ7FkO6skY -klBz9Q//Uw0RGbgOAPchaH2Lkazt0lcMy7gc9hdf7CiscnPVa6MKS9lVKLXFqBvl -nesDtXBphk1n+tLzGwNyyB9hFRCEQv+PepGhJBScMmrtuRDEpW18Jq4WPW/gKzdS -xes9bJbmic0jJxrVL562CGWF+/qBJ3Xbh0SFLnbPBmRaHwFcalLrCwoCV70f5/5R -altDrF/V325DYlgrghNcyxYq5EdWTCUacH1kdDUIZmhEw4/KKnW0dG6F1o8Ee5E0 -wdQOsirtNrtbkMSTXyWt6EZZfanRDeIjkbG3v4vZy/I1GxGqqhX+9Mp6C7mEzFUQ -rGw2+xXekA6r2RBr80RKKroAisBabiO7I5ilsiJKdYGz5IJEpA4Y42d2uX9SkQSZ -iBjteHYrSPriPGmLAI3Idp6KhM8ux15lXaU1iXK8hkvR+uVKgL/q6piJwqpkJM6m -9kdW/ik6+7cDBPAs71K2Pe9udgvvHCxD/BI40N5xAlZgaVpAYmb4Ru1ndaPAG/DT -GfL3AkpHmnkwOFy2lbeRFDSgeLAIL0LdOpOQfuIQdhrXfAWkxeAOu4sXVKJlSDRr -p9cc6KUus6R4nOpCpbdE56VEo+KXaU+Iil2eLBevUk35rkuN/TyshbCz0hJ1E7y+ -oJduLbUhQrxA+wb7YfccNbCTvJR4p4tZu/jAqJ7mPQUJ3p4wc38= -=ebyQ +klB+AA/8D3g1f0uTJa+nMTdKsWlgF0qwXNP+2+Y5zHY93Th6+6bN+Q+NlJkQxvGM +LAyPGVcUWIreIYNuJzt/fXqqK0XTyrCl5zWUiniWZZEP9QGXsSiv1GU5rHUHJH3j +OX9/0QGrw9afjxVMvVwHTtn09bEFCE0JeGfE/nE66Rjaq3Wk9DXaPtqqDqwQbvGw +FuAtiDdbar3ddwKtdbTpwjpY/x2inD3AmHzrak/cwErfpzSpZWzjIw3sAN/dq7oO +13lQAazOTUNMrUlNpLsaCAiCa/Lpa0usWTXcp2etYphvDHnjP2PtxO+DE2dlPjVY +oj15fJmvUfPvZa7gwpKo9V4/bEE6mk0++XPRtgNAZVn9qXPgVbv87DZfxPflUENl +zi2cYczu/XRAJF8MnNInd3RullGshkvainpofnq/ZABcHigqBjXY+jWrHPzRXByK +lVm8Dh2QRsGa4D6qS1f/iB5XYKeaXjZOaccZNXkC8FECB/pA0p7zXDX9rao+asbb +O78BQZvsWasvK98lj2kt0SzciP9cZh1nJZVWnViRr7whBavBrN8+4FAezOsPpsWo +ndY/LxVphiOPrHY+oLcRA3jStHOs1tr2huGpO5ux6uDvO152LI9dGa4DkDoQf8/f +2eOBsIe2iQwM3kf77y0Cgmg2a2hBODmqxrA0FqLMtDQdBVscpt4= +=TcjO -----END PGP SIGNATURE----- diff --git a/metadata/glsa/Manifest.files.gz b/metadata/glsa/Manifest.files.gz index 18c8fa3d4261..88517ac8974b 100644 Binary files a/metadata/glsa/Manifest.files.gz and b/metadata/glsa/Manifest.files.gz differ diff --git a/metadata/glsa/glsa-201805-04.xml b/metadata/glsa/glsa-201805-04.xml new file mode 100644 index 000000000000..f63ce11ab625 --- /dev/null +++ b/metadata/glsa/glsa-201805-04.xml @@ -0,0 +1,48 @@ + + + + rsync: Arbitrary command execution + A vulnerability in rsync might allow remote attackers to execute + arbitrary commands. + + rsync + 2018-05-08 + 2018-05-08 + 646818 + remote + + + 3.1.3 + 3.1.3 + + + +

File transfer program to keep remote files into sync.

+
+ +

A vulnerability was discovered in rsync’s parse_arguments function in + options.c. +

+
+ +

Remote attackers could possibly execute arbitrary commands with the + privilege of the process. +

+
+ +

There is no known workaround at this time.

+
+ +

All rsync users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.1.3" + +
+ + CVE-2018-5764 + + Zlogene + b-man +
diff --git a/metadata/glsa/timestamp.chk b/metadata/glsa/timestamp.chk index 72b494a0407a..55a4a1351eb4 100644 --- a/metadata/glsa/timestamp.chk +++ b/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Tue, 08 May 2018 12:08:21 +0000 +Fri, 11 May 2018 14:08:22 +0000 diff --git a/metadata/glsa/timestamp.commit b/metadata/glsa/timestamp.commit index 94cb37af3cfa..80519ec96966 100644 --- a/metadata/glsa/timestamp.commit +++ b/metadata/glsa/timestamp.commit @@ -1 +1 @@ -e5c04f29237a0b5ac8d5c241b6f686f89d46e211 1525305465 2018-05-02T23:57:45+00:00 +b65153089d9ef7671aaa737050c3a53cb35a1893 1525793297 2018-05-08T15:28:17+00:00 -- cgit v1.2.3