You are here
News
US Employee Engagement Sinks To 10-Year Low
Read more of this story at Slashdot.
Annual US Dementia Cases Projected to Rise to 1 Million by 2060
Read more of this story at Slashdot.
Supreme Court Allows Hawaii To Sue Oil Companies Over Climate Change Effects
Read more of this story at Slashdot.
Ministers Mull Allowing Private Firms to Make Profit From NHS Data In AI Push
Read more of this story at Slashdot.
Meta Is Blocking Links to Decentralized Instagram Competitor Pixelfed
Read more of this story at Slashdot.
Linus Torvalds Offers to Build Guitar Effects Pedal For Kernel Developer
Read more of this story at Slashdot.
CEO of AI Music Company Says People Don't Like Making Music
Read more of this story at Slashdot.
New York Starts Enforcing $15 Broadband Law That ISPs Tried To Kill
Read more of this story at Slashdot.
Euro-Cloud Anexia Moves 12,000 VMs Off VMware to Homebrew KVM Platform
Read more of this story at Slashdot.
Mastodon Announces Transition To Nonprofit Structure
Read more of this story at Slashdot.
EU Probes Apple's New App Store Fees
Read more of this story at Slashdot.
After Years of USB Word Salad, New Labels Strip Everything But the Speed
Read more of this story at Slashdot.
Microsoft Is Testing 45% M365 Price Hikes in Asia
Read more of this story at Slashdot.
Companies Deploy AI To Curb Hiring as 'Cost Avoidance' Gains Ground
Read more of this story at Slashdot.
Ghost Jobs Haunt Online Listings
Read more of this story at Slashdot.
Nvidia Snaps Back at Biden's 'Innovation-Killing' AI Chip Export Restrictions
Read more of this story at Slashdot.
FBI Chief Warns China Poised To Wreak 'Real-World Harm' on US Infrastructure
Read more of this story at Slashdot.
Sonos CEO Patrick Spence Steps Down After Disastrous App Launch
Read more of this story at Slashdot.
DSA-5843-1 rsync - security update
CVE-2024-12084
Simon Scannell, Pedro Gallegos and Jasiel Spelman discovered a heap-based buffer overflow vulnerability due to improper handling of attacker-controlled checksum lengths. A remote attacker can take advantage of this flaw for code execution.
CVE-2024-12085
Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a flaw in the way rsync compares file checksums, allowing a remote attacker to trigger an information leak.
CVE-2024-12086
Simon Scannell, Pedro Gallegos and Jasiel Spelman discovered a flaw which would result in a server leaking contents of an arbitrary file from the client's machine.
CVE-2024-12087
Simon Scannell, Pedro Gallegos and Jasiel Spelman reported a path traversal vulnerability in the rsync daemon affecting the --inc-recursive option, which could allow a server to write files outside of the client's intended destination directory.
CVE-2024-12088
Simon Scannell, Pedro Gallegos and Jasiel Spelman reported that when using the --safe-links option, rsync fails to properly verify if a symbolic link destination contains another symbolic link with it, resulting in path traversal and arbitrary file write outside of the desired directory.
CVE-2024-12747
Aleksei Gorban "loqpa" discovered a race condition when handling symbolic links resulting in an information leak which may enable escalation of privileges.
Neuralink Implants Third Brain Chip. Plans '20 or 30' This Year, Eventually 'Blindsight' Devices
Read more of this story at Slashdot.
Pages
