Scientific Linux Security Update : rsync on SL5.x i386/x86_64

high Nessus Plugin ID 61105

Synopsis

The remote Scientific Linux host is missing a security update.

Description

This updated rsync package fixes the following bug :

- The previous rsync security errata update, which was applied with the rsync tool update to version 3.0.6-4, introduced a patch which fixed the issue with missing memory deallocation. Due to an error in that patch, the following new issue appeared: when specifying the source or destination argument of the rsync command without the optional user@ argument, rsync failed to provide the correct parameters to an external command, such as ssh, and thus rsync failed with an error. With this update, the source code has been modified to fix this issue

Because of the bug, the Scientific Linux Development Team was not able to release the 3.0.6-4 security update.

All users of rsync are advised to upgrade to this updated package, which resolves this bug, and provides the security, bug fixes and enhancements of the 3.0.6-4 errata update.

Solution

Update the affected rsync package.

See Also

http://www.nessus.org/u?fd767218

Plugin Details

Severity: High

ID: 61105

File Name: sl_20110802_rsync_on_SL5_x.nasl

Version: 1.5

Type: local

Agent: unix

Published: 8/1/2012

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 8/2/2011