summaryrefslogtreecommitdiffstats
path: root/scripts/install-buildtools
diff options
context:
space:
mode:
authorArchana Polampalli <archana.polampalli@windriver.com>2025-01-16 15:51:18 +0000
committerSteve Sakoman <steve@sakoman.com>2025-01-24 07:49:28 -0800
commitf70841d2a2321cb5bde9fc784dccd2c18d67354c (patch)
tree6c860d326cdf83b9f48f8030b0ef23a9a5478e03 /scripts/install-buildtools
parent2aebe10959d2343ad4818660bee6ca07fdcfc0dd (diff)
downloadpoky-f70841d2a2321cb5bde9fc784dccd2c18d67354c.tar.gz
rsync: fix CVE-2024-12088
A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory (From OE-Core rev: 741200c41a19ef5b4876d9a80667dfde2e5f4a9d) Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'scripts/install-buildtools')
0 files changed, 0 insertions, 0 deletions