X-Git-Url: https://mattmccutchen.net/rsync/rsync.git/blobdiff_plain/c4a5c57dc3ad079ca7017f1881613937a602e72e..604f343c49fcc8ec396e439cc6146a862a111405:/NEWS diff --git a/NEWS b/NEWS index 3457da16..1322c529 100644 --- a/NEWS +++ b/NEWS @@ -1,36 +1,16 @@ -rsync 2.5.3 (not released yet) +rsync 2.5.4 (13 March 2002) - SECURITY FIXES: - - * Make sure that supplementary groups are removed from a server - process after changing uid and gid. (Ethan Benson) + "Imitation lizard skin" BUG FIXES: - * Fixed problem that in many cases caused the error message - unexpected read size of 0 in map_ptr - and resulted in the wrong data being copied. - - * Fixed compilation errors on some systems caused by the use of - "unsigned int64" in rsync.h. - - * Fixed problem on systems such as Sunos4 that do not support realloc - on a NULL pointer; error was "out of memory in flist_expand". - - * Fix for rsync server processes hanging around after the client - unexpectedly disconnects. (Colin Walters) (Debian bug #128632) - + * Additional fix for zlib double-free bug. (Martin Pool, Andrew + Tridgell) (CVE CAN-2002-0059) + ENHANCEMENTS: - * Command to initiate connections is only shown with -vv, rather - than -v as in 2.5.2. Output from plain -v is more similar to - what was historically used so as not to break scripts that try - to parse the output. - - * Added --no-whole-file and --no-blocking-io options (Dave Dykstra) - - * Made the --write-batch and --read-batch options actually work - and added documentation in the man page (Jos Backus) + * Merge in changes from zlib 1.1.3 to zlib 1.1.4. (Jos Backus) + (Note that rsync still uses a custom version of zlib; you can + not just link against a system library. See zlib/README.rsync) - * If the daemon is unable to fork a child to accept a connection, - print an error message. (Colin Walters) + * Additional test cases for --compress. (Martin Pool)