]> code.ossystems Code Review - openembedded-core.git/commit
rsync: backport a patch to fix CVE-2014-9512
authorRoy Li <rongqing.li@windriver.com>
Fri, 24 Apr 2015 02:37:14 +0000 (10:37 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 15 May 2015 17:12:10 +0000 (18:12 +0100)
commita42af2e434c01c04af36d6ed7a7a5480a7a255a5
tree8f5c6ea7afb3d1cb7c35912cb205de37e6b96d74
parentecf26a6e4aaac6d7f24eeb38215365c4c72b81a8
rsync: backport a patch to fix CVE-2014-9512

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink
attack on a file in the synchronization path.

Backport Complain-if-an-inc-recursive-path-is-not-right-for-i.patch to fix it

(From OE-Core master rev: f280b4f28231ea5a416266ae022d6e4c4ea91117)

Signed-off-by: Roy Li <rongqing.li@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/rsync/rsync-3.1.1/0001-Complain-if-an-inc-recursive-path-is-not-right-for-i.patch [new file with mode: 0644]
meta/recipes-devtools/rsync/rsync_3.1.1.bb