Gentoo Archives: gentoo-mirrors

From: Andrea Barisani <lcars@g.o>
To: gentoo-mirrors@g.o
Subject: [gentoo-mirrors] rsync 2.6.8 security update
Date: Sat, 29 Apr 2006 10:23:28
Hi folks,

rsync 2.6.8 is out and it's being bumped in the portage tree for a security

Quoting release notes:

- The xattrs.diff patch received a security fix that prevents a potential
  buffer overflow in the receive_xattr() code.

Related bug: (still closed but the issue is public anyway)

I updated the server on for testing, after 2.6.0 the
--daemon options changed a bit, quoting changelog:

- The daemon-mode options are now separated from the normal rsync
  options so that they can't be mixed together.  This makes it
  impossible to start a daemon that has improper default option
  values (which could cause problems when a client connects, such as 
  hanging or crashing).

so you might have to strip some options from your command line arguments in
order to start it (and if appliable move them to rsyncd.conf)

More info at


Andrea Barisani <lcars@g.o>                            .*.
Gentoo Linux Infrastructure Developer                          V
                                                             (   )
PGP-Key 0x864C9B9E   (   )
    0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E        ^^_^^
      "Pluralitas non est ponenda sine necessitate"
gentoo-mirrors@g.o mailing list


Subject Author
[gentoo-mirrors] gentoo-portage mirror problems Lior Kaplan <webmaster@×××××××××.il>