Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

openSUSE Leap: 42.3 & 15.0 Moderate: Git-Annex File Disclosure

opensuse
Calendar Grey July 6, 2018
Dist Opensuse Esm H88
A recent patch for git-annex resolves several vulnerabilities in openSUSE. To ensure system integrity, utilize zypper for installation.
An update that fixes two vulnerabilities is now available.

Description

This update for git-annex to version 6.20180626 fixes the following issues:

- CVE-2018-10857: Prevent file content disclosure by refusing to download

content that cannot be verified with a hash, from encrypted special

remotes and glacier (bsc#1098062).

- CVE-2018-10859: Prevent local gpg encrypted file disclosure by refusing

to download content that cannot be verified with a hash, from encrypted

special remotes (bsc#1098364).

This update brings many other bug fixes and new features.

https://hackage.haskell.org/package/git-annex-6.20180626/changelog has a

detailed list of changes.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-697=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-697=1

Package List

- openSUSE Leap 42.3 (x86_64):

git-annex-6.20180626-8.1

git-annex-bash-completion-6.20180626-8.1

- openSUSE Leap 15.0 (x86_64):

git-annex-6.20180626-lp150.2.5.1

git-annex-bash-completion-6.20180626-lp150.2.5.1

References

https://www.suse.com/security/cve/CVE-2018-10857.html

https://www.suse.com/security/cve/CVE-2018-10859.html

https://bugzilla.suse.com/1098062

https://bugzilla.suse.com/1098364

--

Announcement ID: openSUSE-SU-2018:1896-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here