Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 30: 2019-248ad990b4 Critical: Aria2 Password Leak Fix

fedora
Calendar Grey April 12, 2019
Dist Fedora Esm H88
Fedora 30 patch aria2 security update resolves serious credential exposure for HTTP auth, CVE-2019-3501.
Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993)

Summary

aria2 is a download utility with resuming and segmented downloading.

Supported protocols are HTTP/HTTPS/FTP/BitTorrent. It also supports Metalink

version 3.0.

Currently it has following features:

- HTTP/HTTPS GET support

- HTTP Proxy support

- HTTP BASIC authentication support

- HTTP Proxy authentication support

- FTP support(active, passive mode)

- FTP through HTTP proxy(GET command or tunneling)

- Segmented download

- Cookie support

- It can run as a daemon process.

- BitTorrent protocol support with fast extension.

- Selective download in multi-file torrent

- Metalink version 3.0 support(HTTP/FTP/BitTorrent).

- Limiting download/upload speed

Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991

#1663992 #1663993)

[ 1 ] Bug #1663991 - CVE-2019-3500 aria2: Password leak for HTTP based authentication

https://bugzilla.redhat.com/show_bug.cgi?id=1663991

su -c 'dnf upgrade --advisory FEDORA-2019-248ad990b4' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 1.34.0
Release: 4.fc30
Summary: High speed download utility with resuming and segmented downloading

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here