Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 22 CABAL-2015-8206 Critical Update: Upload Command Security

fedora
Calendar Grey June 10, 2015
Dist Fedora Esm H88
Crucial notice regarding cabal-install for Fedora 22 enhances upload protection through compulsory digest verification.
Force cabal upload to always use digest auth and never basic auth Note this only affects uploading of new source tarballs to Hackage by Haskell upstream package maintainers

Summary

The 'cabal' command-line program simplifies the process of managing Haskell

software by automating the fetching, configuration, compilation and

installation of Haskell libraries and programs from Hackage.

Update Information:

Force cabal upload to always use digest auth and never basic auth

Note this only affects uploading of new source tarballs to Hackage by Haskell upstream package maintainers. It is safer to upload packages via the Hackage web interface.

Change Log

* Wed May 13 2015 Jens Petersen - 1.18.1.0-1 - security version update for upload command

References

Fedora Update Notification FEDORA-2015-8206 2015-05-14 20:20:21
Name : cabal-install Product : Fedora 22 Version : 1.18.1.0 Release : 1.fc22 URL : https://hackage.haskell.org/package/cabal-install Summary : Command-line interface for Cabal and Hackage Description : The 'cabal' command-line program simplifies the process of managing Haskell software by automating the fetching, configuration, compilation and installation of Haskell libraries and programs from Hackage.

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update cabal-install' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: cabal-install
Product: Fedora 22
Version: 1.18.1.0
Release: 1.fc22
Summary: Command-line interface for Cabal and Hackage

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here