RHSA-2022:2198: Important: rsync security update
The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.Security Fix(es): zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rsyncto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1 - Upgrade
Upgrade
redhat/rsync-daemonto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1 - Upgrade
Upgrade
redhat/rsync-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1 - Upgrade
Upgrade
redhat/rsync-debugsourceto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1 - Upgrade
Upgrade
redhat/rsyncto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1.aa - Upgrade
Upgrade
redhat/rsync-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1.aa - Upgrade
Upgrade
redhat/rsync-debugsourceto a version that resolves this vulnerability.Fixed in 3.1.3-12.el8_4.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:2198?
The severity of RHSA-2022:2198 is categorized as important.
How do I fix RHSA-2022:2198?
To fix RHSA-2022:2198, update rsync to version 3.1.3-12.el8_4.1 or later.
What software is affected by RHSA-2022:2198?
RHSA-2022:2198 affects the rsync and rsync-daemon packages among others.
Is RHSA-2022:2198 a remote vulnerability?
Yes, RHSA-2022:2198 can be exploited remotely.
What versions of rsync are vulnerable in RHSA-2022:2198?
Versions of rsync prior to 3.1.3-12.el8_4.1 are considered vulnerable in RHSA-2022:2198.