The CVE patches weren't previously applied because they depend on the enableCopyDevicesPatch parameter. The naming of the patches attribute in base.nix was misleading. The new rsync release now really fixes: * CVE-2017-15994 * CVE-2017-16548 * CVE-2017-17433 * CVE-2017-17434 |
||
---|---|---|
.. | ||
acd_cli | ||
backintime | ||
lsyncd | ||
rclone | ||
rsync | ||
unison |