Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2021-0471 Severe: Fossil Arbitrary Command Execution

mageia
Calendar Grey August 30, 2020
Dist Mageia Esm H88
The Fossil software upgrade mitigates the potential for remote unauthorized code execution vulnerability in Mageia 7, offering remedies in update version 2.10.2.
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code

Summary

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614).
The fossil package has been updated to version 2.10.2, containing fixes for this issue, fixes for other bugs and security issues, and additional enhancements. See the changes list for details.

References

- https://bugs.mageia.org/show_bug.cgi?id=27153

- https://www.openwall.com/lists/oss-security/2020/08/25/1

- https://fossil-scm.org/home/doc/trunk/www/changes.wiki

- https://www.cve.org/CVERecord?id=CVE-2020-24614

Resolution

SRPMS

- 7/core/fossil-2.10.2-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 30 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0354.html
Type: security
CVE: CVE-2020-24614

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here