LWN.net Logo

Trustix Secure Linux

From:  Trustix Security Advisor <tsl-AT-trustix.org>
To:  tsl-announce-AT-lists.trustix.org
Subject:  TSL-2004-0026 - rsync
Date:  Fri, 7 May 2004 14:07:54 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Bugfix Advisory #2004-0026

Package name:      rsync
Summary:           fixes a --relative option (-R) in 2.6.1
Date:              2004-05-07
Affected versions: Trustix Secure Linux 1.5
                   Trustix Secure Linux 2.0
                   Trustix Secure Linux 2.1
                   Trustix Secure Enterprise Linux 2

- --------------------------------------------------------------------------
Package description:
  Rsync uses a quick and reliable algorithm to very quickly bring
  remote and host files into sync.  Rsync is fast because it just
  sends the differences in the files over the network (instead of
  sending the complete files). Rsync is often used as a very powerful
  mirroring process or just as a more capable replacement for the
  rcp command.  A technical report which describes the rsync algorithm
  is included in this package.


Problem description:
  rsync 2.6.1 introduced a bug in the sorting of the filenames when
  --relative is used for some sources (just sources such as "/" and
  "/*" were affected).  This fix ensures that we ask for the right
  file-list item when requesting changes from the sender.


Action:
  We recommend that all systems with this package installed be upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All Trustix Secure Linux updates are available from
  <URI:http://http.trustix.org/pub/trustix/updates/>
  <URI:ftp://ftp.trustix.org/pub/trustix/updates/>


About Trustix Secure Linux:
  Trustix Secure Linux is a small Linux distribution for servers. With focus
  on security and stability, the system is painlessly kept safe and up to
  date from day one using swup, the automated software updater.


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.


Public testing:
  Most updates for Trustix Secure Linux are made available for public
  testing some time before release.
  If you want to contribute by testing the various packages in the
  testing tree, please feel free to share your findings on the
  tsl-discuss mailinglist.
  The testing tree is located at
  <URI:http://tsldev.trustix.org/horizon/>

  You may also use swup for public testing of updates:
  
  site {
      class = 0
      location = "http://tsldev.trustix.org/horizon/rdfs/latest.rdf"
      regexp = ".*"
  }
  

Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.org/support/>


Verification:
  This advisory along with all Trustix packages are signed with the
  TSL sign key.
  This key is available from:
  <URI:http://www.trustix.org/TSL-SIGN-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.org/errata/trustix-1.5/>,
  <URI:http://www.trustix.org/errata/trustix-2.0/> and
  <URI:http://www.trustix.org/errata/trustix-2.1/>
  or directly at
  <URI:http://www.trustix.org/errata/2004/0026/>


MD5sums of the packages:
- --------------------------------------------------------------------------
30b7c17bd32980e4a75446f24c002ca2  TSEL-2/rsync-2.6.2-1tr.i586.rpm
77fec2f8a14276c0ca8a972f2e5f3f98  TSEL-2/rsync-server-2.6.2-1tr.i586.rpm
637c1972e4c55dd9968d521606b38019  1.5/rpms/rsync-2.6.2-0.1tr.i586.rpm
c9e6f9ee63ea51bff6f5c0bea96a9bc1  2.0/rpms/rsync-2.6.2-0.1tr.i586.rpm
19f56578dde6bb45a7f2d4ed65120e32  2.0/rpms/rsync-server-2.6.2-0.1tr.i586.rpm
d1dbd184a932d77891ff1412530bda78  2.1/rpms/rsync-2.6.2-1tr.i586.rpm
00ca32e3bb57cce54a584d95ed6ba784  2.1/rpms/rsync-server-2.6.2-1tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFAm3pTi8CEzsK9IksRAioVAJ45YGyf2JAqirlwi8KjkQdzeZ64gwCfaN/m
D3pDzDkwMnjwYXrINDX3MhU=
=t+qS
-----END PGP SIGNATURE-----
_______________________________________________
tsl-announce mailing list
tsl-announce@lists.trustix.org
http://lists.trustix.org/mailman/listinfo/tsl-announce


(Log in to post comments)

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds