Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39 FEDORA-2024-35147eb6ad Critical Opentofu Command Execution

fedora
Calendar Grey August 8, 2024
Dist Fedora Esm H88
Fedora 39 launches opentofu version 1.8.0 addressing severe vulnerabilities such as unauthorized command execution.
Update to 1.8.0 Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789

Summary

OpenTofu lets you declaratively manage your cloud infrastructure.

Update Information:

Update to 1.8.0 Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789

Change Log

* Mon Jul 29 2024 Mikel Olasagasti Uranga - 1.8.0-1 - Update to 1.8.0 - Closes rhbz#2300353 * Sat Jul 27 2024 Mikel Olasagasti Uranga - 1.7.3-3 - Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789 - Closes rhbz#2294255 rhbz#2294007 rhbz#2292714 * Thu Jul 18 2024 Fedora Release Engineering - 1.7.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2292714 - CVE-2024-24789 opentofu: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292714 [ 2 ] Bug #2294007 - CVE-2024-6104 opentofu: go-retryablehttp: url might write sensitive information to log file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2294007 [ 3 ] Bug #2294255 - CVE-2024-6257 opentofu: hashicorp/go-getter: Arbitrary command execution through local git config file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2294255

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-35147eb6ad' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: opentofu
Product: Fedora 39
Version: 1.8.0
Release: 1.fc39
Summary: OpenTofu lets you declaratively manage your cloud infrastructure

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here