Scientific Linux Security Update : rsync on SL5.x i386/x86_64

This script is Copyright (C) 2012 Tenable Network Security, Inc.


Synopsis :

The remote Scientific Linux host is missing a security update.

Description :

This updated rsync package fixes the following bug :

- The previous rsync security errata update, which was
applied with the rsync tool update to version 3.0.6-4,
introduced a patch which fixed the issue with missing
memory deallocation. Due to an error in that patch, the
following new issue appeared: when specifying the source
or destination argument of the rsync command without the
optional user@ argument, rsync failed to provide the
correct parameters to an external command, such as ssh,
and thus rsync failed with an error. With this update,
the source code has been modified to fix this issue

Because of the bug, the Scientific Linux Development Team was not able
to release the 3.0.6-4 security update.

All users of rsync are advised to upgrade to this updated package,
which resolves this bug, and provides the security, bug fixes and
enhancements of the 3.0.6-4 errata update.

See also :

http://www.nessus.org/u?3412a06d

Solution :

Update the affected rsync package.

Risk factor :

High

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 61105 ()

Bugtraq ID:

CVE ID: