MGASA-2015-0409

Source
https://advisories.mageia.org/MGASA-2015-0409.html
Import Source
https://advisories.mageia.org/MGASA-2015-0409.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0409
Published
2015-10-25T14:38:05Z
Modified
2026-04-16T04:27:58Z
Summary
Updated rsync packages fix security vulnerability
Details

Michael Samuel discovered that rsync was vulnerable to checksum collisions. This could prevent rsync from running and syncing files successfully, which could break various applications that use and rely on rsync (rhbz#1197601).

The patched rsync will now operate in a way that is not vulnerable to this issue as long as both the rsync client and rsync server support the new 'C' option that has been added. This issue is similar to an issue in librsync which was fixed in MGASA-2015-0146.

References
Credits

Affected packages

Mageia:5 / rsync

Package

Name
rsync
Purl
pkg:rpm/mageia/rsync?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.1-5.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0409.json"