{"id":"MGASA-2015-0409","summary":"Updated rsync packages fix security vulnerability","details":"Michael Samuel discovered that rsync was vulnerable to checksum\ncollisions. This could prevent rsync from running and syncing files\nsuccessfully, which could break various applications that use and rely on\nrsync (rhbz#1197601).\n\nThe patched rsync will now operate in a way that is not vulnerable to this\nissue as long as both the rsync client and rsync server support the new\n'C' option that has been added.  This issue is similar to an issue in\nlibrsync which was fixed in MGASA-2015-0146.\n","modified":"2026-04-16T04:27:58.799616Z","published":"2015-10-25T14:38:05Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0409.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=16969"}],"affected":[{"package":{"name":"rsync","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/rsync?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1-5.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0409.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}