The package fossil before version 2.16-1 is vulnerable to certificate verification bypass. . Arch Linux Security Advisory ASA-202108-8 ======================================== Severity: High Date : 2021-08-10 CVE-ID : CVE-2021-36377 Package : fossil Type : certificate verification bypass Remote : Yes Link : https://security.archlinux.org/AVG-2146 Summary ====== The package fossil before version 2.16-1 is vulnerable to certificate verification bypass. Resolution ========= Upgrade to 2.16-1. # pacman -Syu "fossil> =2.16-1" The problem has been fixed upstream in version 2.16. Workaround ========= None. Description ========== Fossil before version 2.15.2 often skips the hostname check during TLS certificate validation. Impact ===== A man-in-the-middle attacker could spoof a Fossil repository by presenting any valid certificate for an arbitrary hostname, leading to potential information disclosure. References ========= https://fossil-scm.org/forum/forumpost/8d367e16f53d93c789d70bd3bf2c9587227bbd5c6a7b8e512cccd79007536036 https://fossil-scm.org/home/info/aaab2a15d1dfc22f5453c2bad8f25ecf518ed3eef9a7fa6f4c5bd69ab4e4b075 https://security.archlinux.org/CVE-2021-36377 . Debian Security Bulletin DSA-2021-4567 highlights a severe vulnerability in libxml2 prior to version 2.9.10 that could lead to XML entity expansion.. Fossil Certificate Bypass, Arch Linux Security, Package Advisory. . LinuxSecurity.com Team
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for . MGASA-2020-0354 - Updated fossil package fixes security vulnerability Publication date: 30 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0354.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24614 Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for this issue, fixes for other bugs and security issues, and additional enhancements. See the changes list for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27153 - https://www.openwall.com/lists/oss-security/2020/08/25/1 - https://fossil-scm.org/home/doc/trunk/www/changes.wiki - https://www.cve.org/CVERecord?id=CVE-2020-24614 SRPMS: - 7/core/fossil-2.10.2-1.mga7 . The Fossil software upgrade mitigates the potential for remote unauthorized code execution vulnerability in Mageia 7, offering remedies in update version 2.10.2.. Fossil Package, Mageia Security, Remote Execution Fix, CVE-2020-24614. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.