Login
Newsletter
Werbung

Sicherheit: Unsichere Verwendung temporärer Dateien in fedup
Aktuelle Meldungen Distributionen
Name: Unsichere Verwendung temporärer Dateien in fedup
ID: FEDORA-2014-14027
Distribution: Fedora
Plattformen: Fedora 20
Datum: Sa, 1. November 2014, 07:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6494
Applikationen: fedup

Originalnachricht

Name        : fedup
Product : Fedora 20
Version : 0.9.0
Release : 1.fc20
URL : https://github.com/wgwoods/fedup
Summary : The Fedora Upgrade tool
Description :
fedup is the Fedora Upgrade tool.

-------------------------------------------------------------------------------
-
Update Information:

* Adds `--product=PRODUCT` flag, required for upgrades to F21
* Uses host's config files in `upgrade.img`, which should fix various
upgrade problems (e.g. incorrect keyboard layout when unlocking disks due to missing `vconsole.conf`)
* Logging improvements: complete upgrade log should appear in system journal
-------------------------------------------------------------------------------
-
ChangeLog:

* Wed Oct 29 2014 Will Woods <wwoods@redhat.com> 0.9.0-1
- Add --product=PRODUCT flag for upgrades to F21
- Use host's config files in upgrade.img
- Fix logging during upgrade - upgrade logs will appear in system journal
- Fix keymap problems during upgrade (#1038413)
- Move cache to /var/cache (#1066679, CVE-2013-6494)
* Sat Jun 7 2014 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 0.8.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu May 22 2014 Will Woods <wwoods@redhat.com> 0.8.1-1
- Warn the user when there is no kernel package in the upgrade
- Fix crash when resizing terminal window (#1044987)
- Fix crashes with bad arguments to --repo and --iso (#1045090, #1044083)
- Fix some crashes during transaction test (#1043981, #1047005)
- Fix upgrade hang if packagedir isn't on root partition (#1045168)
- Don't redownload everything if the user just upgraded from 0.7.x
* Fri Feb 28 2014 Adam Williamson <awilliam@redhat.com> 0.8.0-4
- backport a few more bugfixes from git master:
+ fix upgrade startup when packagedir isn't on root (#1045168)
+ Fix --network VERSION if /etc/debian_release exists (#1057817)
+ Warn the user if upgrade contains no kernels
- bump the required systemd version (also a 'backport' from git)
* Tue Dec 10 2013 Will Woods <wwoods@redhat.com> 0.8.0-3
- Fix crash with Ctrl-C on F18
- Fix --instrepo with --device/--iso
* Wed Dec 4 2013 Will Woods <wwoods@redhat.com> 0.8.0-0
- Check signatures on downloaded packages and images (#877623)
- Added --nogpgcheck, --instrepokey, --enableplugin, --disableplugin
- Improve error messages and warnings about transaction problems
- Improve disk space error messages (#949963)
- Clarify "instrepo not found" error (#980818)
- Start upgrade using systemd generator instead of boot args (#964303)
- Fix emergency shell on F17 upgrades (#958586)
- Don't start upgrade if media/packages are missing (#984415)
- Check for mismatched instrepo arch (#981180)
- Fix traceback with deltarpm (#1005895)
- Use the right kernel for Xen guests (#1023618)
- Fix mirror failover for instrepo (#1027573)
- Download multiple packages in parallel for extra speed
- Lots of other bugfixes
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1066679 - CVE-2013-6494 fedup: /var/tmp/fedora-upgrade temporary
directory creation vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1066679
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update fedup' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung