Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42: reposurgeon 5.3 Update Targeting CVE-2025-22870 DoS Issue

fedora
Calendar Grey August 3, 2025
Dist Fedora Esm H88
Fedora 42 refreshes reposurgeon to version 5.3, addressing the HTTP proxy circumvention vulnerability, thus enhancing security measures.
reposurgeon: update to 5.3 version

Summary

Reposurgeon enables risky operations that version-control systems don't want

to let you do, such as editing past comments and metadata and removing

commits. It works with any version control system that can export and import

git fast-import streams, including git, hg, fossil, bzr, CVS and RCS. It can

also read Subversion dump files directly and can thus be used to script

production of very high-quality conversions from Subversion to any supported

DVCS.

Update Information:

reposurgeon: update to 5.3 version

Change Log

* Fri Jul 25 2025 Denis Fateyev - 5.3-1 - Disable go vet in tests - Update to 5.3 * Fri Jul 25 2025 Fedora Release Engineering - 5.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sat Jan 18 2025 Fedora Release Engineering - 5.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

References


[ 1 ] Bug #2341281 - reposurgeon: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2341281 [ 2 ] Bug #2346712 - reposurgeon-5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2346712 [ 3 ] Bug #2352330 - CVE-2025-22870 reposurgeon: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2352330

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-19c41f754c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: reposurgeon
Product: Fedora 42
Version: 5.3
Release: 1.fc42
Summary: SCM Repository Manipulation Tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here