Re: [DSA 1360-1] New rsync packages fix arbitrary code execution

2007-08-29 Thread Steve Kemp
On Tue Aug 28, 2007 at 15:24:24 -0400, Simon Valiquette wrote: > > Stable updates are available for alpha, amd64, arm, hppa, i386, > > ia64, mips, mipsel, powerpc, s390 and sparc. > > > > There is no updated packages for Debian Etch PowerPC, contrarily > to what is stated on the previous line.

Re: [DSA 1360-1] New rsync packages fix arbitrary code execution

2007-08-28 Thread Simon Valiquette
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Steve Kemp un jour écrivit: > > Sebastian Krahmer discovered that rsync, a fast remote file copy > program, contains an off-by-one error which might allow remote > attackers to execute arbitary code via long directory names. > > For the stable di