An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for git-annex ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1897-1 Rating: moderate References: #1098062 #1098364 Cross-References: CVE-2018-10857 CVE-2018-10859 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for git-annex to version 6.20180626 fixes the following issues: - CVE-2018-10857: Prevent file content disclosure by refusing to download content that cannot be verified with a hash, from encrypted special remotes and glacier (bsc#1098062). - CVE-2018-10859: Prevent local gpg encrypted file disclosure by refusing to download content that cannot be verified with a hash, from encrypted special remotes (bsc#1098364). This update brings many other bug fixes and new features. https://hackage.haskell.org/package/git-annex-6.20180626/changelog has a detailed list of changes. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-697=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): git-annex-6.20180626-7.1 git-annex-bash-completion-6.20180626-7.1 References: https://www.suse.com/security/cve/CVE-2018-10857.html https://www.suse.com/security/cve/CVE-2018-10859.html https://bugzilla.suse.com/1098062 https://bugzilla.suse.com/1098364 -- . Update for git-annex available on openSUSE addressing potential information leakage with filecontent. Detailed patching steps provided.. openSUSE Security, git-annex Fix, contingency measures, disclosure prevention. . LinuxSecurity.com Team
Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to . Hash: SHA512 Package : drupal7 Version : 7.14-2+deb7u16 CVE ID : CVE-2017-6922 Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system. For Debian 7 "Wheezy", these problems have been fixed in version 7.14-2+deb7u16. We recommend that you upgrade your drupal7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the security of private file uploads for unauthenticated users on a Debian Wheezy system with Drupal 7 by following essential best practices and updates. drupal7 update, Debian security, anonymous file upload, access control update, file protection fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.