Mention the security fix.

This commit is contained in:
Wayne Davison
2004-08-12 20:58:33 +00:00
parent 6f0fc27e33
commit 8fb7db245a

8
NEWS
View File

@@ -2,6 +2,14 @@ NEWS for rsync 2.6.3 (UNRELEASED)
Protocol: 28 (unchanged)
Changes since 2.6.2:
SECURITY FIXES:
- A bug in the sanitize_path routine (which affects a non-chrooted
rsync daemon) could allow a user to specify an absolute path for
certain options (but not for file-transfer names). If you're running
a rsync daemon with chroot disabled, *please upgrade*, ESPECIALLY if
the user privs you run rsync under is anything above "nobody".
OUTPUT CHANGES (ATTN: those using a script to parse the verbose output):
- Please note that the 2-line footer (output when verbose) now uses the