<?xml version="1.0" encoding="UTF-8"?>

<rdf:RDF 
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns="http://purl.org/rss/1.0/"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:syn="http://purl.org/rss/1.0/modules/syndication/"
>

  <channel rdf:about="http://lwn.net/headlines/61541/">
    <title>LWN: Comments on "Remotely exploitable heap overflow in rsync"</title>
    <link>http://lwn.net/Articles/61541/</link>
    <description>
This is a special feed containing comments posted
to the individual LWN article titled &quot;Remotely exploitable heap overflow in rsync&quot;.

    </description>

    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>2</syn:updateFrequency>
    <items>
      <rdf:Seq>
	<rdf:li resource="http://lwn.net/Articles/61654/rss" />
	<rdf:li resource="http://lwn.net/Articles/61644/rss" />
	<rdf:li resource="http://lwn.net/Articles/61643/rss" />
	<rdf:li resource="http://lwn.net/Articles/61630/rss" />
	<rdf:li resource="http://lwn.net/Articles/61629/rss" />
	<rdf:li resource="http://lwn.net/Articles/61592/rss" />
	<rdf:li resource="http://lwn.net/Articles/61587/rss" />
	<rdf:li resource="http://lwn.net/Articles/61586/rss" />
	<rdf:li resource="http://lwn.net/Articles/61576/rss" />
	<rdf:li resource="http://lwn.net/Articles/61567/rss" />
	<rdf:li resource="http://lwn.net/Articles/61562/rss" />
      
      </rdf:Seq>
    </items>

  </channel>
    <item rdf:about="http://lwn.net/Articles/61654/rss">
      <title>new Debian package is uploaded</title>
      <link>http://lwn.net/Articles/61654/rss</link>
      <dc:date>2003-12-05T05:24:15+00:00</dc:date>
      <dc:creator>proski</dc:creator>
      <description>
      There are new updates in unstable. Python is fixed. It happened just an hour after my previous post. Quite a coincidence.
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61644/rss">
      <title>new Debian package is uploaded</title>
      <link>http://lwn.net/Articles/61644/rss</link>
      <dc:date>2003-12-05T03:26:01+00:00</dc:date>
      <dc:creator>proski</dc:creator>
      <description>
      Debian unstable still has no updates. In addition to that, there is a &lt;a href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=222088&quot;&gt;dependency problem that prevents upgrading Python&lt;/a&gt;. Such problems are normally resolved next day, but now we are stuck in this state for more than a week.
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61643/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61643/rss</link>
      <dc:date>2003-12-05T02:44:18+00:00</dc:date>
      <dc:creator>fLameDogg</dc:creator>
      <description>
      Neener ;O) 
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61630/rss">
      <title>Duh</title>
      <link>http://lwn.net/Articles/61630/rss</link>
      <dc:date>2003-12-04T23:34:27+00:00</dc:date>
      <dc:creator>JoeBuck</dc:creator>
      <description>
      &lt;p&gt;
Ignore previous comment; I went directly to the story from Slashdot so I didn't see the teaser item on the main LWN page.

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61629/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61629/rss</link>
      <dc:date>2003-12-04T23:33:17+00:00</dc:date>
      <dc:creator>JoeBuck</dc:creator>
      <description>
      &lt;p&gt;
Any connection to the Gentoo attack?

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61592/rss">
      <title>new Debian package is uploaded</title>
      <link>http://lwn.net/Articles/61592/rss</link>
      <dc:date>2003-12-04T20:45:17+00:00</dc:date>
      <dc:creator>stevenj</dc:creator>
      <description>
      I just checked, and an rsync_2.5.5-0.2 package has apparently just been uploaded to the Debian security server; the changelog indicates that it is for the bug reported here.&lt;p&gt;Those guys are fast.
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61587/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61587/rss</link>
      <dc:date>2003-12-04T20:14:04+00:00</dc:date>
      <dc:creator>Ross</dc:creator>
      <description>
      Doh.  And I meant to say &amp;quot;shouldn't&amp;quot;.
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61586/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61586/rss</link>
      <dc:date>2003-12-04T20:13:02+00:00</dc:date>
      <dc:creator>Ross</dc:creator>
      <description>
      But it should say &amp;quot;contains&amp;quot; :)
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61576/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61576/rss</link>
      <dc:date>2003-12-04T19:31:22+00:00</dc:date>
      <dc:creator>smoogen</dc:creator>
      <description>
      Please note that this vulnerability only affects the use of rsync as a&lt;br&gt;&amp;quot;rsync server&amp;quot;. To see if you are running a rsync server you should&lt;br&gt;use the netstat command to see if you are listening on TCP port&lt;br&gt;873. If you are not listening on TCP port 873 then you are not running&lt;br&gt;a rsync server.&lt;p&gt;--&lt;p&gt;Or have been rooted already and netstat has been replaced.
      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61567/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61567/rss</link>
      <dc:date>2003-12-04T19:14:53+00:00</dc:date>
      <dc:creator>hamjudo</dc:creator>
      <description>
      All the previous versions that support the remote protocol, &lt;i&gt;rsync server&lt;/i&gt;, are vulnerable.
See
&lt;a href=http://rsync.samba.org/&gt;rsync.samba.org&lt;/a&gt;
for a revised announcement.&lt;p&gt;
It now says &lt;br&gt;- rsync version &lt;b&gt;2.5.6 and earlier&lt;/b&gt; contains a heap overflow...

      
      </description>
    </item>
    <item rdf:about="http://lwn.net/Articles/61562/rss">
      <title>Remotely exploitable heap overflow in rsync</title>
      <link>http://lwn.net/Articles/61562/rss</link>
      <dc:date>2003-12-04T18:44:46+00:00</dc:date>
      <dc:creator>utoddl</dc:creator>
      <description>
      What about versions prior to 2.5.6?  The article isn't clear on that.
      
      </description>
    </item>
</rdf:RDF>

