X-Git-Url: https://mattmccutchen.net/rsync/rsync.git/blobdiff_plain/6dfb45bcdf7f40e970a7be7bb67a567dd1484744..43a4dc1053bd3bfec67f3cc6a6fa4edc1f394a82:/NEWS diff --git a/NEWS b/NEWS index 317b2b0e..668d915b 100644 --- a/NEWS +++ b/NEWS @@ -1,27 +1,16 @@ -rsync 2.5.3 (not released yet) +rsync 2.5.4 (12 March 2002) - SECURITY FIXES: - - * Make sure that supplementary groups are removed from a server - process after changing uid and gid. (Ethan Benson) + "Imitation lizard skin" BUG FIXES: - * Fixed problem that in many cases caused the error message - unexpected read size of 0 in map_ptr - and resulted in the wrong data being copied. - - * Fixed compilation errors on some systems caused by the use of - "unsigned int64" in rsync.h. - + * Additional fix for zlib double-free bug. (Martin Pool, Andrew + Tridgell) (CVE CAN-2002-0059) + ENHANCEMENTS: - * Command to initiate connections is only shown with -vv, rather - than -v as in 2.5.2. Output from plain -v is more similar to - what was historically used so as not to break scripts that try - to parse the output. - - * Added --no-whole-file and --no-blocking-io options (Dave Dykstra) + * Merge in changes from zlib 1.1.3 to zlib 1.1.4. (Jos Backus) + (Note that rsync still uses a custom version of zlib; you can + not just link against a system library. See zlib/README.rsync) - * Made the --write-batch and --read-batch options actually work - and added documentation in the man page (Jos Backus) + * Additional test cases for --compress. (Martin Pool)