Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 28: Security Advisory for Git-Annex Addressing Data Exposure

fedora
Calendar Grey July 11, 2018
Dist Fedora Esm H88
A recent git-annex security update addresses vulnerabilities linked to unauthorized access to sensitive data and possible server misuse on Fedora 28 with full update details available
Update to 6.20180626 Security fix for CVE-2018-10857 and CVE-2018-10859

Summary

Git-annex allows managing files with git, without checking the file contents

into git. While that may seem paradoxical, it is useful when dealing with files

larger than git can currently easily handle, whether due to limitations in

memory, time, or disk space.

It can store large files in many places, from local hard drives, to a large

number of cloud storage services, including S3, WebDAV, and rsync, with a dozen

cloud storage providers usable via plugins. Files can be stored encrypted with

gpg, so that the cloud storage provider cannot see your data.

git-annex keeps track of where each file is stored, so it knows how many copies

are available, and has many facilities to ensure your data is preserved.

git-annex can also be used to keep a folder in sync between computers, noticing

when files are changed, and automatically committing them to git and

transferring them to other computers. The git-annex webapp makes it easy to set

up and use git-annex this way.

Update to 6.20180626 Security fix for CVE-2018-10857 and CVE-2018-10859

* Thu Jun 28 2018 Elliott Sales de Andrade - 6.20180626-1

- update to 6.20180626

- Fix CVE-2018-10857 and CVE-2018-10859 (#1595634)

* Fri Apr 20 2018 Elliott Sales de Andrade - 6.20180409-1

- update to 6.20180409

[ 1 ] Bug #1595631 - CVE-2018-10857 git-annex: Private data exposure and exfiltration

https://bugzilla.redhat.com/show_bug.cgi?id=1595631

[ 2 ] Bug #1595633 - CVE-2018-10859 git-annex: Malicious server could trick git-annex into decrypting a file encrypted to the user's gpg key

https://bugzilla.redhat.com/show_bug.cgi?id=1595633

su -c 'dnf upgrade --advisory FEDORA-2018-e22c8eb218' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N27SN5NCGQYHJ6OQMHGUO7OBWRDYDIXM/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 6.20180626
Release: 1.fc28
Summary: Manage files with git, without checking their contents into git

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here