summaryrefslogtreecommitdiffstats
path: root/scripts/install-buildtools
diff options
context:
space:
mode:
authorArchana Polampalli <archana.polampalli@windriver.com>2025-01-16 15:51:19 +0000
committerSteve Sakoman <steve@sakoman.com>2025-01-24 07:49:28 -0800
commitb4825be8068153c45308e108dfdaf67e8ebd84d9 (patch)
tree00d02933abb44d133d3d56411e9b65720bb30a7b /scripts/install-buildtools
parentf70841d2a2321cb5bde9fc784dccd2c18d67354c (diff)
downloadpoky-b4825be8068153c45308e108dfdaf67e8ebd84d9.tar.gz
rsync: fix CVE-2024-12747
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation. (From OE-Core rev: c0905ffb2f1aa3bc4c6187ff4860dcc8d3dbfb01) Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'scripts/install-buildtools')
0 files changed, 0 insertions, 0 deletions