{"id":"CLSA-2025-1738632046","summary":"Fix CVE(s): CVE-2024-12086, CVE-2024-12087, CVE-2024-12088","details":"   * SECURITY UPDATE: possible information leak via checksum comparison\n     - debian/patches/CVE-2024-12086.patch: fix info leak when connecting\n       to malicious server\n     - CVE-2024-12086\n   * SECURITY UPDATE: arbitraty file write via inproper symlink verification\n     - debian/patches/CVE-2024-12087.patch: fix writing malicious files\n       to arbitrary locations when using '--inc-recursive' option\n     - CVE-2024-12087\n   * SECURITY UPDATE: arbitraty file write when using '--safe-links' option\n     - debian/patches/CVE-2024-12088.patch: properly verify if a symbolic\n       link destination contains another symbolic link within it when using\n       the '--safe-links' option\n     - CVE-2024-12088","modified":"2026-06-04T09:46:38.106422698Z","published":"2025-02-04T01:20:52Z","upstream":["CVE-2024-12086","CVE-2024-12087","CVE-2024-12088"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2025-1738632046.html"}],"affected":[{"package":{"name":"rsync","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/rsync?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1-3ubuntu1.3+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1738632046.json"}}],"schema_version":"1.7.5"}