Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE 15-SP2: 2021:1070-1 Important: Remote Code Execution Fix

opensuse
Calendar Grey July 21, 2021
Scroller Opensuse
Important openSUSE patch for git addresses vulnerabilities linked to potential remote code execution and brings improvements.
An update that solves one vulnerability and has one errata is now available

Description

This update for fossil fixes the following issues:

- fossil 2.12.1:

* CVE-2020-24614: Remote authenticated users with check-in or

administrative privileges could have executed arbitrary code

[boo#1175760]

* Security fix in the "fossil git export" command. New "safety-net"

features were added to prevent similar problems in the future.

* Enhancements to the graph display for cases when there are many

cherry-pick merges into a single check-in. Example

* Enhance the fossil open command with the new --workdir option and the

ability to accept a URL as the repository name, causing the remote

repository to be cloned automatically. Do not allow "fossil open" to

open in a non-empty working directory unless the --keep option or the

new --force option is used.

* Enhance the markdown formatter to more closely follow the CommonMark

specification with regard to text highlighting. Underscores in the

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2021-1070=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

fossil-2.12.1-bp152.2.9.1

References

https://www.suse.com/security/cve/CVE-2020-24614.html

https://bugzilla.suse.com/1047218

https://bugzilla.suse.com/1175760

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1070-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.