Re: Serious rsync security issues

From: Liam Proven <liam.proven_at_sitpub.com>
Date: Fri, 17 Jan 2025 11:49:03 UTC
On Thu, 16 Jan 2025 at 23:16, Vincent Miller <vrwmiller@gmail.com> wrote:
>
> The port is at 3.4.1. If I'm not mistaken the vulnerabilities are in 3.4.0.

You _are_ mistaken. 3.4.0 was the version that fixed the issues.

The most serious issue, CVSS 9.8, affects all versions since 3.2.7.
The other 5 affect all known versions.

-- 
Liam Proven ~ lproven@sitpub.com
Open Source Reporter, the Register ~ https://www.theregister.com/
Isle of Man tel: +44 7624 227612 ~ UK tel: +44 7939 087884 (*not* 24x7)
Czech tel: +420 702 829 053 (also WhatsApp/Telegram/Signal)