Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 28: Security Advisory for myrepos CVE-2018-7032 Critical Fix

fedora
Calendar Grey August 7, 2018
Dist Fedora Esm H88
Critical security patch for myrepos on Fedora 28 addressing major issues with CVE-2018-7032 vulnerabilities.
Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

Summary

The mr command can checkout, update, or perform other actions on

a set of repositories as if they were one combined repository. It

supports any combination of subversion, git, cvs, mecurial, bzr and

darcs repositories, and support for other revision control systems

can easily be added.

Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

* Sat Jul 28 2018 Fabian Affolter - 1.20180726-1

- Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)

- Update to new upstream version 1.20180726

* Fri Jul 13 2018 Fedora Release Engineering - 1.20171231-3

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

* Thu Jun 28 2018 Jitka Plesnikova - 1.20171231-2

- Perl 5.28 rebuild

* Sat May 5 2018 Fabian Affolter - 1.20171231-1

- Update to new upstream version 1.20171231

* Thu Feb 8 2018 Fedora Release Engineering - 1.20160123-6

- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[ 1 ] Bug #1383312 - myrepos: Missing URL sanitization in webcheckout

https://bugzilla.redhat.com/show_bug.cgi?id=1383312

su -c 'dnf upgrade --advisory FEDORA-2018-f17daf1cd6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OJWODJX6HNSGKBN2CTEHRT5QLFQXTVQS/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 1.20180726
Release: 1.fc28
URL: Summary : A multiple SCM repository management tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here