openSUSE-SU-2020:1478-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1478-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2020:1478-1
Upstream
Related
Published
2020-09-19T22:23:30Z
Modified
2026-02-04T03:34:52Z
Summary
Security update for fossil
Details

This update for fossil fixes the following issues:

  • fossil 2.12.1:

    • CVE-2020-24614: Remote authenticated users with check-in or administrative privileges could have executed arbitrary code [boo#1175760]
    • Security fix in the 'fossil git export' command. New 'safety-net' features were added to prevent similar problems in the future.
    • Enhancements to the graph display for cases when there are many cherry-pick merges into a single check-in. Example
    • Enhance the fossil open command with the new --workdir option and the ability to accept a URL as the repository name, causing the remote repository to be cloned automatically. Do not allow 'fossil open' to open in a non-empty working directory unless the --keep option or the new --force option is used.
    • Enhance the markdown formatter to more closely follow the CommonMark specification with regard to text highlighting. Underscores in the middle of identifiers (ex: fossil_printf()) no longer need to be escaped.
    • The markdown-to-html translator can prevent unsafe HTML (for example:
References

Affected packages

SUSE:Package Hub 15 SP1 / fossil

Package

Name
fossil
Purl
pkg:rpm/suse/fossil&distro=SUSE%20Package%20Hub%2015%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.1-bp152.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "fossil":  "2.12.1-bp152.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1478-1.json"

SUSE:Package Hub 15 SP2 / fossil

Package

Name
fossil
Purl
pkg:rpm/suse/fossil&distro=SUSE%20Package%20Hub%2015%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.1-bp152.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "fossil":  "2.12.1-bp152.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1478-1.json"

openSUSE:Leap 15.1 / fossil

Package

Name
fossil
Purl
pkg:rpm/opensuse/fossil&distro=openSUSE%20Leap%2015.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.1-bp152.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "fossil":  "2.12.1-bp152.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1478-1.json"

openSUSE:Leap 15.2 / fossil

Package

Name
fossil
Purl
pkg:rpm/opensuse/fossil&distro=openSUSE%20Leap%2015.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.1-bp152.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "fossil":  "2.12.1-bp152.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1478-1.json"