Client-side TLS so that it verifies that the server hostname matches its certificate (Fixed in fossil 2.14.2). A data exfiltration bug in the server (Fixed in fossil 2.14.1). . MGASA-2021-0491 - Updated fossil packages fix security vulnerability Publication date: 27 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0491.html Type: security Affected Mageia releases: 8 CVE: Client-side TLS so that it verifies that the server hostname matches its certificate (Fixed in fossil 2.14.2). A data exfiltration bug in the server (Fixed in fossil 2.14.1). References: - https://bugs.mageia.org/show_bug.cgi?id=29266 - https://fossil-scm.org/home/doc/trunk/www/changes.wiki#v2_14 - - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.