insecure

3 stories and discussions about insecure, aggregated from every source we track.

1.

<strong>apt-listchanges --which=both -f text --since=3.4.1+ds1-5+deb13u4 <br> /var/cache/apt/archives/rsync_3.5.0+ds1-0+deb13u1_amd64.deb apt-listchanges: Reading changelogs... apt-listchanges: News</strong> <p>rsync (3.5.0+ds1-0+deb13u1) trixie-security; urgency=medium</p> <p>In order to fix 33 CVEs, I have decided to bump the package to 3.5.0 rather than backporting all patches individually. After analysing the extra changes from the bump, not included in the CVE fixes, I have concluded this approach carries the lower amount of risk compared to the alternative.</p> <p>This update contains behavior changes, all of which stems from the CVE fixes themselves, not exclusive to the version bump. The ones most likely to break an existing setup are listed here; /usr/share/doc/rsync/NEWS.md.gz has the full list.</p> <p>Operator-supplied paths are no longer followed through untrusted symlinks. The destination directory and the arguments to --backup-dir, --temp-dir, --partial-dir, --link-dest, --compare-dest, --copy-dest, --log-file, --password-file, --files-from, --include-from, --exclude-from, --write-batch, --read-batch and --filter merge files are now resolved one component at a time, following a symlink only when it is owned by root or by the user running rsync; one owned by anyone else is refused with "refusing to follow a symlink owned by an untrusted user". --insecure-links restores the old behaviour, but it is local only and a daemon never honours it. For a single trusted module, set "insecure links = yes" in that module instead.</p> <p>rrsync now refuses --debug on every invocation. When restricted to a subdirectory it additionally denies --copy-unsafe-links, passes the new --confine-root so the server will not resolve a client-named filter merge file outside that directory, and passes --drop-D when receiving, so an upload can no longer create devices or special files there ("skipping non-regular file"). A plain "rsync -a" otherwise still works.</p> <p>--chmod=a+s now sets both the setuid and setgid bits, matching chmod(1); it previously set setuid alone.</p> <p>rsyncd changes that can change who gets in:</p> <ul> <li>"proxy protocol = true" without "proxy protocol hosts" now rejects every connection and warns at startup, instead of trusting a client-supplied PROXY header.</li> <li>"hosts deny" now fails closed when a configured hostname cannot be resolved (with "forward lookup", the default), so a host previously admitted by an unresolvable deny entry is now blocked.</li> <li>"auth users" values that start with a comma now split on commas alone, as documented, so a deny or :ro rule naming a group whose name contains a space now takes effect where it was silently ignored.</li> <li>"hosts allow" / "hosts deny" patterns now fold case inside a [...] bracket expression as well, so a rule such as [A-Z]* matches hosts it used to miss.</li> <li>A client-requested --compress-threads is capped at 8.</li> </ul> <p>rsync-ssl now verifies the server certificate. The default openssl backend additionally binds it to the requested hostname, so a certificate valid for some other name is now rejected. The stunnel and gnutls backends refuse to run unless RSYNC_SSL_CA_CERT is set, or RSYNC_SSL_ALLOW_INSECURE_STUNNEL=1 / RSYNC_SSL_ALLOW_INSECURE_GNUTLS=1 is set to opt out.</p> <p>-- Samuel Henrique <a href="mailto:[email protected]" rel="ugc">[email protected]</a> Tue, 15 Sep 2026 18:46:30 -0700</p>

7 points•janus•about 5 hours ago•0 comments
2.

Stay updated with insights on developer productivity, AI-native engineering, and organizational transformation.

1 points•jcs•over 13 years ago•0 comments
3.

OpenAI says it has canceled plans to release its updated GPT-6.1 model next month as it continues to investigate what testing shows to be a regression in terms of safety compared to previous models. The move, first reported by The Wall Street Journal late Monday and later confirmed in OpenAI statements to the press, reflects what OpenAI Head of Safety Systems Saachi Jain said was a "trade off" between performance and security seen when testing the now-scrapped model. Jain said GPT-6.1 was better than previous models at sticking with difficult tasks all the way to completion without human intervention. But the model was also more likely to fail tests related to alignment (i.e. staying within the bounds set by human creators) and more willing to use sometimes "unsafe" tools and services to push ahead with a task. It was also more likely to try to deceive end users about actions it did or didn't take, Jain said. Last week, OpenAI said it was halting training of its "most capable models" following an incident where a model attempted to circumvent Internet access restrictions. GPT-6.1 was not among those "most capable models" covered by that move, OpenAI told the WSJ. And while GPT-6.1 won't be released as is, the company said it intends to use the same base model for further training runs that it said will hopefully lead to future GPT-6 generation models. Read full article Comments

0 points•Kyle Orland•1 day ago•0 comments

Related topics