Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 41: FEDORA-2024-4f08c1a90a critical: age authorization bypass

fedora
Calendar Grey December 27, 2024
Dist Fedora Esm H88
Upgrade to Fedora 41 to address age tool's authorization bypass issue. Major enhancements for security integrated.
Update to 1.2.1 to fix https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c security issue.

Summary

A simple, modern and secure encryption tool (and Go library) with small

explicit keys, no config options, and UNIX-style composability.

Update Information:

Update to 1.2.1 to fix https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c security issue.

Change Log

* Wed Dec 18 2024 Mikel Olasagasti Uranga - 1.2.1-1 - Update to 1.2.1 - Closes rhbz#2333048

References


[ 1 ] Bug #2331964 - CVE-2024-45337 age: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331964

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4f08c1a90a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: age
Product: Fedora 41
Version: 1.2.1
Release: 1.fc41
Summary: Simple, modern and secure encryption tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here