RSYNC Vulnerability Announcement (Upgrade Patch Pushed)

RSYNC Vulnerability Announcement (Upgrade Patch Pushed)

At 02:25 Beijing time on January 15, 2025, security researcher Nick Tait reported six security vulnerabilities in rsync on the oss-security mailing list. Among them, the most severe vulnerability allows attackers to execute arbitrary code on the server simply by having anonymous read access to the rsync server (such as a public mirror). Vulnerability Details: CVE-2024-12084 (CVSS: 9.8): There is a heap buffer overflow vulnerability in rsync due to improper handling of checksum lengths. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), attackers can perform out-of-bounds writes in the sum2 buffer. Affected versions: 3.2.7 to 3.4.0. CVE-2024-12085 (CVSS: 7.5): In ...Read more

deepin Community Monthly Report | The 14th DDUC Successfully Held in Wuhan, Multiple New Developments in Community SIGs

deepin Community Monthly Report | The 14th DDUC Successfully Held in Wuhan, Multiple New Developments in Community SIGs

Overview of deepin community data for December   deepin Community products 1、deepin 23 Product Updates and User Feedback deepin 23 Update In December 2024, deepin 23 was updated in beta three times. The main focus of this month was to fix security vulnerabilities to continuously improve system security. deepin Home In December 2024, Depth Home received a total of 176 bug and feature feedback from users: Among them, there were 128 bug reports, 4 of which have been fixed, and 13 confirmed issues pending resolution; There were 48 feature requests, 8 of which have been completed, and 13 have been ...Read more

deepin Bi-Weekly Technical Report: deepin 25 Focuses on Bug Fixes, Launches x86 Device Compatibility...

deepin Bi-Weekly Technical Report: deepin 25 Focuses on Bug Fixes, Launches x86 Device Compatibility...

The ninth Issue of deepin Biweekly Technical Report has been released, we will briefly list the progress of various deepin teams over the past two weeks and outline the general plan for the next two weeks!   DDE(deepin Desktop Environment) Requirements development for deepin 25 has been completed, and the current phase is focused on bug fixes for deepin 23 and deepin 25. Progress Fine-tune the visual effects of DTK's menu and scrollbar components. Continuously fix bugs in DDE components such as the taskbar and notifications based on community feedback. Adjust the technical preview interface to add a restart prompt ...Read more

deepin Bi-Weekly Technical Report:  DDE 7.0 to be Released with deepin 25 Preview

deepin Bi-Weekly Technical Report: DDE 7.0 to be Released with deepin 25 Preview

The eighth Issue of deepin Biweekly Technical Report has been released, we will briefly list the progress of various deepin teams over the past two weeks and outline the general plan for the next two weeks!   DDE(deepin Desktop Environment) Requirements development for deepin 25 has been completed, and the current phase is focused on bug fixes for deepin 23 and deepin 25. Progress Further improve the adaptation support for Treeland; Fix several Qt and DDE issues discovered during the Wayland adaptation process. Plans Prepare for the release of DDE 7.0 with the deepin 25 Preview.   System Development Progress ...Read more

deepin Bi-Weekly Technical Report: deepin 23, deepin 25 BUG fixes, Treeland implements personalized wallpaper configurations

deepin Bi-Weekly Technical Report: deepin 23, deepin 25 BUG fixes, Treeland implements personalized wallpaper configurations

The seventh Issue of deepin Biweekly Technical Report has been released, we will briefly list the progress of various deepin teams over the past two weeks and outline the general plan for the next two weeks!   DDE(deepin Desktop Environment) Requirements development for deepin 25 has been completed, and the current phase is focused on bug fixes for deepin 23 and deepin 25. Progress Further optimization of the taskbar application recognition feature to address specific boundary case issues; Fixes and improvements to several QML versions of the Control Center; Improvements to the dde-shell experience for the Treeland environment; Fixing a ...Read more

deepin Community Monthly Report for November 2024

deepin Community Monthly Report for November 2024

Overview of deepin community data for October   deepin Community products 1、Major Upgrade of deepin IDE: New Features such as smart terminals have been added In November 2024, deepin IDE received a major upgrade. This update focused on the following features: Inline chat function: users can select a function to ask questions, supporting intelligent editing and quick Q&A. Codebase feature: quickly understand the functionality of unfamiliar code projects and locate specific features in the project. Intelligent Q&A function in the terminal: enables users to perform intelligent queries, such as weather inquiries. 2、deepin 23 Product Updates and User Feedback deepin 23 ...Read more