In the download utility aria2, --log was leaking HTTP user credentials in local log file. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2873-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for aria2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1125-1 Rating: moderate References: #1189107 Cross-References: CVE-2019-3500 CVSS scores: CVE-2019-3500 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 openSUSE Backports SLE-15-SP3 openSUSE Backports SLE-15-SP2 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for aria2 fixes the following issues: Update to version 1.35.0: * Drop SSLv3.0 and TLSv1.0 and add TLSv1.3 * TLSv1.3 support is added for GNUTLS and OpenSSL. * Platform: Fix compilation without deprecated OpenSSL APIs * Remove linux getrandom and use C++ stdlib instead * Don't send Accept Metalink header if Metalink is disabled - Move bash completion to better location Update to version 1.34.0: * UnknownLengthPieceStorage: return piece length show something in console status when downloading items with unknown content length * Fix bug that signal handler does not work with libaria2 when aria2::RUN_ONCE is passed to aria2::run(). * Retry on HTTP 502 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1125=1 - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1125=1 - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-1125=1 - openSUSE Backports SLE-15-SP1: zypper in -tpatch openSUSE-2021-1125=1 Package List: - openSUSE Leap 15.2 (noarch): aria2-lang-1.35.0-lp152.5.3.1 - openSUSE Leap 15.2 (x86_64): aria2-1.35.0-lp152.5.3.1 aria2-debuginfo-1.35.0-lp152.5.3.1 aria2-debugsource-1.35.0-lp152.5.3.1 aria2-devel-1.35.0-lp152.5.3.1 libaria2-0-1.35.0-lp152.5.3.1 libaria2-0-debuginfo-1.35.0-lp152.5.3.1 - openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64): aria2-1.35.0-bp153.2.3.1 aria2-debuginfo-1.35.0-bp153.2.3.1 aria2-debugsource-1.35.0-bp153.2.3.1 aria2-devel-1.35.0-bp153.2.3.1 libaria2-0-1.35.0-bp153.2.3.1 libaria2-0-debuginfo-1.35.0-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (noarch): aria2-lang-1.35.0-bp153.2.3.1 - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): aria2-1.35.0-bp152.4.3.1 aria2-debuginfo-1.35.0-bp152.4.3.1 aria2-debugsource-1.35.0-bp152.4.3.1 aria2-devel-1.35.0-bp152.4.3.1 libaria2-0-1.35.0-bp152.4.3.1 libaria2-0-debuginfo-1.35.0-bp152.4.3.1 - openSUSE Backports SLE-15-SP2 (noarch): aria2-lang-1.35.0-bp152.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): aria2-1.35.0-bp151.5.3.1 aria2-devel-1.35.0-bp151.5.3.1 libaria2-0-1.35.0-bp151.5.3.1 - openSUSE Backports SLE-15-SP1 (noarch): aria2-lang-1.35.0-bp151.5.3.1 References: https://www.suse.com/security/cve/CVE-2019-3500.html https://bugzilla.suse.com/1189107 . A new patch for openSUSE is out, tackling a moderate vulnerability involving aria2, complete with comprehensive installation guidelines.. OpenSUSE Security, Aria2 Update, Patch Instructions. . LinuxSecurity.com Team
Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-8b8c774b84 2019-04-29 01:08:43.319939 --------------------------------------------------------------------------------Name : aria2 Product : Fedora 28 Version : 1.34.0 Release : 4.fc28 URL : http://aria2.github.io/ Summary : High speed download utility with resuming and segmented downloading Description : aria2 is a download utility with resuming and segmented downloading. Supported protocols are HTTP/HTTPS/FTP/BitTorrent. It also supports Metalink version 3.0. Currently it has following features: - HTTP/HTTPS GET support - HTTP Proxy support - HTTP BASIC authentication support - HTTP Proxy authentication support - FTP support(active, passive mode) - FTP through HTTP proxy(GET command or tunneling) - Segmented download - Cookie support - It can run as a daemon process. - BitTorrent protocol support with fast extension. - Selective download in multi-file torrent - Metalink version 3.0 support(HTTP/FTP/BitTorrent). - Limiting download/upload speed --------------------------------------------------------------------------------Update Information: Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993) --------------------------------------------------------------------------------ChangeLog: * Wed Mar 27 2019 Athmane Madjoudj - 1.34.0-4 - Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993) * Thu Jan 31 2019 Fedora Release Engineering - 1.34.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Thu Jul 12 2018 Fedora Release Engineering - 1.34.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Mon May 21 2018 Athmane Madjoudj - 1.34.0-1 - Update to 1.34.0 (rhbz#1580169) --------------------------------------------------------------------------------References: [ 1 ] Bug #1663991 - CVE-2019-3500 aria2: Password leak for HTTP based authentication https://bugzilla.redhat.com/show_bug.cgi?id=1663991 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-8b8c774b84' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-248ad990b4 2019-04-13 00:02:00.007274 --------------------------------------------------------------------------------Name : aria2 Product : Fedora 30 Version : 1.34.0 Release : 4.fc30 URL : http://aria2.github.io/ Summary : High speed download utility with resuming and segmented downloading Description : aria2 is a download utility with resuming and segmented downloading. Supported protocols are HTTP/HTTPS/FTP/BitTorrent. It also supports Metalink version 3.0. Currently it has following features: - HTTP/HTTPS GET support - HTTP Proxy support - HTTP BASIC authentication support - HTTP Proxy authentication support - FTP support(active, passive mode) - FTP through HTTP proxy(GET command or tunneling) - Segmented download - Cookie support - It can run as a daemon process. - BitTorrent protocol support with fast extension. - Selective download in multi-file torrent - Metalink version 3.0 support(HTTP/FTP/BitTorrent). - Limiting download/upload speed --------------------------------------------------------------------------------Update Information: Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993) --------------------------------------------------------------------------------References: [ 1 ] Bug #1663991 - CVE-2019-3500 aria2: Password leak for HTTP based authentication https://bugzilla.redhat.com/show_bug.cgi?id=1663991 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-248ad990b4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-248ad990b4 2019-04-13 00:02:00.007274 --------------------------------------------------------------------------------Name : aria2 Product : Fedora 30 Version : 1.34.0 Release : 4.fc30 URL : http://aria2.github.io/ Summary : High speed download utility with resuming and segmented downloading Description : aria2 is a download utility with resuming and segmented downloading. Supported protocols are HTTP/HTTPS/FTP/BitTorrent. It also supports Metalink version 3.0. Currently it has following features: - HTTP/HTTPS GET support - HTTP Proxy support - HTTP BASIC authentication support - HTTP Proxy authentication support - FTP support(active, passive mode) - FTP through HTTP proxy(GET command or tunneling) - Segmented download - Cookie support - It can run as a daemon process. - BitTorrent protocol support with fast extension. - Selective download in multi-file torrent - Metalink version 3.0 support(HTTP/FTP/BitTorrent). - Limiting download/upload speed --------------------------------------------------------------------------------Update Information: Fix Password leak for HTTP based authentication CVE-2019-3500 (rhbz #1663991 #1663992 #1663993) --------------------------------------------------------------------------------References: [ 1 ] Bug #1663991 - CVE-2019-3500 aria2: Password leak for HTTP based authentication https://bugzilla.redhat.com/show_bug.cgi?id=1663991 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-248ad990b4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the --log option. This might allow local users to obtain sensitive information by reading this file. . Package : aria2 Version : 1.18.8-1+deb8u1 CVE ID : CVE-2019-3500 Debian Bug : 918058 It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the --log option. This might allow local users to obtain sensitive information by reading this file. For Debian 8 "Jessie", this problem has been fixed in version 1.18.8-1+deb8u1. We recommend that you upgrade your aria2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Aria2 patch addresses sensitive data exposure vulnerability on Debian Wheezy. Implement the update promptly to protect your system from unauthorized local access threats.. aria2 update, Debian LTS, command line software, security fix. . Severity: Important. LinuxSecurity.com Team
It was observed that URL's which gets downloaded via "--log=" attribute stores sensitive information. This update fixes that. References: - https://bugs.mageia.org/show_bug.cgi?id=24112 . MGASA-2019-0036 - Updated aria2 package fixes security vulnerability Publication date: 15 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0036.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3500 It was observed that URL's which gets downloaded via "--log=" attribute stores sensitive information. This update fixes that. References: - https://bugs.mageia.org/show_bug.cgi?id=24112 - https://www.cve.org/CVERecord?id=CVE-2019-3500 SRPMS: - 6/core/aria2-1.25.0-1.1.mga6 . MGASA-2019-0036 - Updated aria2 package fixes security vulnerability Publication date: 15 Jan 2019 U. observed, url's, which, downloaded, '--log=', attribute, stores, sensitive, information. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for aria2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0050-1 Rating: moderate References: #1120488 Cross-References: CVE-2019-3500 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for aria2 fixes the following security issue: - CVE-2019-3500: Metadata and potential password leaks via --log (boo#1120488) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-50=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-50=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-50=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): aria2-1.24.0-4.4.1 aria2-debuginfo-1.24.0-4.4.1 aria2-debugsource-1.24.0-4.4.1 aria2-devel-1.24.0-4.4.1 libaria2-0-1.24.0-4.4.1 libaria2-0-debuginfo-1.24.0-4.4.1 - openSUSE Leap 42.3 (noarch): aria2-lang-1.24.0-4.4.1 - openSUSE Leap 15.0 (x86_64): aria2-1.33.1-lp150.2.4.1 aria2-debuginfo-1.33.1-lp150.2.4.1 aria2-debugsource-1.33.1-lp150.2.4.1 aria2-devel-1.33.1-lp150.2.4.1 libaria2-0-1.33.1-lp150.2.4.1 libaria2-0-debuginfo-1.33.1-lp150.2.4.1 - openSUSE Leap 15.0 (noarch): aria2-lang-1.33.1-lp150.2.4.1 - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): aria2-1.33.1-bp150.3.7.1 aria2-devel-1.33.1-bp150.3.7.1 libaria2-0-1.33.1-bp150.3.7.1 - openSUSE Backports SLE-15 (noarch): aria2-lang-1.33.1-bp150.3.7.1 References: https://www.suse.com/security/cve/CVE-2019-3500.html https://bugzilla.suse.com/1120488 -- . A new revision for Fedora addresses a significant vulnerability in curl regarding data integrity and possible credential exposure.. openSUSE Update, aria2 Security Patch, Risk Management, Threat Mitigation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.