MGASA-2021-0491
Dashboard / Vulnerabilities / MGASA-2021-0491
Summary: Updated fossil packages fix security vulnerability
Details: Client-side TLS so that it verifies that the server hostname matches its certificate (Fixed in fossil 2.14.2). A data exfiltration bug in the server (Fixed in fossil 2.14.1).
References: https://advisories.mageia.org/MGASA-2021-0491.html, https://bugs.mageia.org/show_bug.cgi?id=29266, https://fossil-scm.org/home/doc/trunk/www/changes.wiki#v2_14, https://lists.opensuse.org/archives/list/[email protected]/thread/AQ44KVDTB6D2MENE7C2YPVCSV3BXT3B4/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JBTRZ5HCOUTIIKJF3T37NORI4P7EVYCY/
Affected packages
Package
Name: fossil
Purl: pkg:rpm/mageia/fossil?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
