An update that solves 3 vulnerabilities can now be installed.. # opentofu-1.9.1-1.1 on GA media Announcement ID: openSUSE-SU-2025:15030-1 Rating: moderate Cross-References: * CVE-2024-45336 * CVE-2024-45341 * CVE-2025-22866 CVSS scores: * CVE-2024-45336 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-45341 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-22866 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22866 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the opentofu-1.9.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * opentofu 1.9.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45336.html * https://www.suse.com/security/cve/CVE-2024-45341.html * https://www.suse.com/security/cve/CVE-2025-22866.html . The latest openSUSE Tumbleweed update resolves several moderate vulnerabilities found in the opentofu package, enhancing overall system protection.. openSUSE Tumbleweed, opentofu update, moderate security advisory, security issues, software vulnerabilities. . LinuxSecurity.com Team
Update to 1.8.0 Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c83208238d 2024-08-08 02:40:51.386017 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 40 Version : 1.8.0 Release : 1.fc40 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.8.0 Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789 -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 29 2024 Mikel Olasagasti Uranga - 1.8.0-1 - Update to 1.8.0 - Closes rhbz#2300353 * Sat Jul 27 2024 Mikel Olasagasti Uranga - 1.7.3-3 - Fix for CVE-2024-6257 CVE-2024-6104 CVE-2024-24789 - Closes rhbz#2294255 rhbz#2294007 rhbz#2292714 * Thu Jul 18 2024 Fedora Release Engineering - 1.7.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292714 - CVE-2024-24789 opentofu: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292714 [ 2 ] Bug #2294007 - CVE-2024-6104 opentofu: go-retryablehttp: url might write sensitive information to log file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2294007 [ 3 ] Bug #2294255 - CVE-2024-6257 opentofu: hashicorp/go-getter: Arbitrary command execution through local git config file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2294255 -------------------------------------------------------------------------------- This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c83208238d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.