Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 27: Critical Update for Myrepos Input Sanitization Issue

fedora
Calendar Grey August 7, 2018
Dist Fedora Esm H88
Important patch for Fedora 27 targeting CVE-2018-7032 within myrepos utility. Vital for upholding system integrity.
Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

Summary

The mr command can checkout, update, or perform other actions on

a set of repositories as if they were one combined repository. It

supports any combination of subversion, git, cvs, mecurial, bzr and

darcs repositories, and support for other revision control systems

can easily be added.

Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

* Sat Jul 28 2018 Fabian Affolter - 1.20180726-1

- Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

- Update to new upstream version 1.20180726

* Fri Jul 13 2018 Fedora Release Engineering - 1.20171231-3

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

* Thu Jun 28 2018 Jitka Plesnikova - 1.20171231-2

- Perl 5.28 rebuild

* Sat May 5 2018 Fabian Affolter - 1.20171231-1

- Update to new upstream version 1.20171231

* Thu Feb 8 2018 Fedora Release Engineering - 1.20160123-6

- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[ 1 ] Bug #1383312 - myrepos: Missing URL sanitization in webcheckout

https://bugzilla.redhat.com/show_bug.cgi?id=1383312

su -c 'dnf upgrade --advisory FEDORA-2018-ee076d0530' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NICCDVJ62Q32F2CRQ6V4Q6LBWKAQLGJH/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 1.20180726
Release: 1.fc27
URL: Summary : A multiple SCM repository management tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here