Alerts This Week
Warning Icon 1 929
Alerts This Week
Warning Icon 1 929

openSUSE: 2020:1478-1 Important: Fossil Remote Code Execution Risk

opensuse
Calendar Grey September 20, 2020
Dist Opensuse Esm H88
This enhancement addresses a critical vulnerability in the fossil system, mitigating the potential for unauthorized code execution by external attackers.
An update that solves one vulnerability and has one errata is now available.

Description

This update for fossil fixes the following issues:

- fossil 2.12.1:

* CVE-2020-24614: Remote authenticated users with check-in or

administrative privileges could have executed arbitrary code

[boo#1175760]

* Security fix in the "fossil git export" command. New "safety-net"

features were added to prevent similar problems in the future.

* Enhancements to the graph display for cases when there are many

cherry-pick merges into a single check-in. Example

* Enhance the fossil open command with the new --workdir option and the

ability to accept a URL as the repository name, causing the remote

repository to be cloned automatically. Do not allow "fossil open" to

open in a non-empty working directory unless the --keep option or the

new --force option is used.

* Enhance the markdown formatter to more closely follow the CommonMark

specification with regard to text highlighting. Underscores in the

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1478=1

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1478=1

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-1478=1

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2020-1478=1

Package List

- openSUSE Leap 15.2 (x86_64):

fossil-2.12.1-lp152.2.3.1

fossil-debuginfo-2.12.1-lp152.2.3.1

fossil-debugsource-2.12.1-lp152.2.3.1

- openSUSE Leap 15.1 (x86_64):

fossil-2.12.1-lp151.3.6.1

fossil-debuginfo-2.12.1-lp151.3.6.1

fossil-debugsource-2.12.1-lp151.3.6.1

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

fossil-2.12.1-bp152.2.3.1

fossil-debuginfo-2.12.1-bp152.2.3.1

fossil-debugsource-2.12.1-bp152.2.3.1

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

fossil-2.12.1-bp151.4.6.1

References

https://www.suse.com/security/cve/CVE-2020-24614.html

https://bugzilla.suse.com/1047218

https://bugzilla.suse.com/1175760

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1478-1
Rating: important
Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 openSUSE Backports SLE-15-SP2 openSUSE Backports SLE-15-SP1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here