概述
Moderate: librepo security update
类型/严重性
Security Advisory: Moderate
Red Hat Lightspeed patch analysis
标题
An update for librepo is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
描述
The librepo library provides a C and Python API to download repository metadata.
Security Fix(es):
- librepo: missing path validation in repomd.xml may lead to directory traversal (CVE-2020-14352)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
受影响的产品
-
Red Hat Enterprise Linux Server 7 x86_64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
-
Red Hat Enterprise Linux Workstation 7 x86_64
-
Red Hat Enterprise Linux Desktop 7 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 7 s390x
-
Red Hat Enterprise Linux for Power, big endian 7 ppc64
-
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
-
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
修复
-
BZ - 1866498
- CVE-2020-14352 librepo: missing path validation in repomd.xml may lead to directory traversal
注::
可能有这些软件包的更新版本。
点击软件包名称查看详情。
Red Hat Enterprise Linux Server 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| x86_64 |
|
librepo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 56bde00fdd27b2a407084b8e3c604878a2961fbbc6a46ef759c9b8b0a054e5f1 |
|
librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: efedfa9ec355a641af00980eb61425edf78cdbdbc0cf944d3575c384d3c2bcfa |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-devel-1.8.1-8.el7_9.i686.rpm
|
SHA-256: a4ab1c2bcb23ea934e0add59a16234a2b6911a7ca7d8d1e90710bffaff4b2deb |
|
librepo-devel-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 3e71417cfdc1dc2b85487cd287e911c9031da01a6d4e2fc92878ba417301a920 |
|
python-librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 1dc33def0597e6f906ea5ea547a76e86c3fda03da44fb0c31c1e12b431974edc |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| x86_64 |
|
librepo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 56bde00fdd27b2a407084b8e3c604878a2961fbbc6a46ef759c9b8b0a054e5f1 |
|
librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: efedfa9ec355a641af00980eb61425edf78cdbdbc0cf944d3575c384d3c2bcfa |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-devel-1.8.1-8.el7_9.i686.rpm
|
SHA-256: a4ab1c2bcb23ea934e0add59a16234a2b6911a7ca7d8d1e90710bffaff4b2deb |
|
librepo-devel-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 3e71417cfdc1dc2b85487cd287e911c9031da01a6d4e2fc92878ba417301a920 |
|
python-librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 1dc33def0597e6f906ea5ea547a76e86c3fda03da44fb0c31c1e12b431974edc |
Red Hat Enterprise Linux Workstation 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| x86_64 |
|
librepo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 56bde00fdd27b2a407084b8e3c604878a2961fbbc6a46ef759c9b8b0a054e5f1 |
|
librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: efedfa9ec355a641af00980eb61425edf78cdbdbc0cf944d3575c384d3c2bcfa |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-devel-1.8.1-8.el7_9.i686.rpm
|
SHA-256: a4ab1c2bcb23ea934e0add59a16234a2b6911a7ca7d8d1e90710bffaff4b2deb |
|
librepo-devel-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 3e71417cfdc1dc2b85487cd287e911c9031da01a6d4e2fc92878ba417301a920 |
|
python-librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 1dc33def0597e6f906ea5ea547a76e86c3fda03da44fb0c31c1e12b431974edc |
Red Hat Enterprise Linux Desktop 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| x86_64 |
|
librepo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 56bde00fdd27b2a407084b8e3c604878a2961fbbc6a46ef759c9b8b0a054e5f1 |
|
librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: efedfa9ec355a641af00980eb61425edf78cdbdbc0cf944d3575c384d3c2bcfa |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-devel-1.8.1-8.el7_9.i686.rpm
|
SHA-256: a4ab1c2bcb23ea934e0add59a16234a2b6911a7ca7d8d1e90710bffaff4b2deb |
|
librepo-devel-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 3e71417cfdc1dc2b85487cd287e911c9031da01a6d4e2fc92878ba417301a920 |
|
python-librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 1dc33def0597e6f906ea5ea547a76e86c3fda03da44fb0c31c1e12b431974edc |
Red Hat Enterprise Linux for IBM z Systems 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| s390x |
|
librepo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 9f0ce6bfbc6a586e540d18043218d838f5785007de3d924b387eb4176055422f |
|
librepo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 8b5a37a3baa8ff8001f1b77993ec1545e4949b852d10604da54d745d0b6c68f3 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 7a0d75bafcaa4f8558348166dded55c04110e9ea56fef6f65b70c20c57409cd5 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 7a0d75bafcaa4f8558348166dded55c04110e9ea56fef6f65b70c20c57409cd5 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: d877f1f20f4c5d37a231f50cc1a4141d57ed479c5ddadd40047f0f3f32a79bcb |
|
librepo-debuginfo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: d877f1f20f4c5d37a231f50cc1a4141d57ed479c5ddadd40047f0f3f32a79bcb |
|
librepo-devel-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 1389843b7c01a104412f3e607fe71c521623095bce1f4e23da017fae07e2661d |
|
librepo-devel-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 5d192daa3ed176b4622c6ed1e98f2944191586d0ed56ece3e4dacf514cdeaea7 |
|
python-librepo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 1cb23cfdd5aee769578d99f23bed83065fec41e9191f7a6e7dbbef8c1d79656f |
Red Hat Enterprise Linux for Power, big endian 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| ppc64 |
|
librepo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: 1249f1880a175ce6ef13ea64f9b05936038370ee0cd4aaaa0007d767d8ab3c30 |
|
librepo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 18141f9f9ddd668c93afa037e27d2a68d04af821150565e588ec523bb6e34547 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: bca4e1b206dd845e15f00758babe6d33661f36d75a77d767573742c3eae219cb |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: bca4e1b206dd845e15f00758babe6d33661f36d75a77d767573742c3eae219cb |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: bc41da68812eabb3a666efbc6e2d561fdbe0f318fdfda7327488bf4220c613f1 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: bc41da68812eabb3a666efbc6e2d561fdbe0f318fdfda7327488bf4220c613f1 |
|
librepo-devel-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: 55effabbbaed42b710917a2ecbacbef8e595ea4208632d4ea0ab9cadad0c5dc3 |
|
librepo-devel-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 4ebd2c95cf26e993429ce39789d128a8d09c908e0423d41e5464d16f4788ea97 |
|
python-librepo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 6c9899464089f7f94ea815d8f3ba446a8ffe4e8b074b7eeceed9e76139841872 |
Red Hat Enterprise Linux for Scientific Computing 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| x86_64 |
|
librepo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 56bde00fdd27b2a407084b8e3c604878a2961fbbc6a46ef759c9b8b0a054e5f1 |
|
librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: efedfa9ec355a641af00980eb61425edf78cdbdbc0cf944d3575c384d3c2bcfa |
|
librepo-debuginfo-1.8.1-8.el7_9.i686.rpm
|
SHA-256: 31e44bc12d15abe4e95d85739579f98c782b87c0e97ab9df68ced5afef21a1ae |
|
librepo-debuginfo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 7e6cc8ef6a1dfe32261b1657717205313d75fbaae74564624b01a61fd8c275b3 |
|
librepo-devel-1.8.1-8.el7_9.i686.rpm
|
SHA-256: a4ab1c2bcb23ea934e0add59a16234a2b6911a7ca7d8d1e90710bffaff4b2deb |
|
librepo-devel-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 3e71417cfdc1dc2b85487cd287e911c9031da01a6d4e2fc92878ba417301a920 |
|
python-librepo-1.8.1-8.el7_9.x86_64.rpm
|
SHA-256: 1dc33def0597e6f906ea5ea547a76e86c3fda03da44fb0c31c1e12b431974edc |
Red Hat Enterprise Linux for Power, little endian 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| ppc64le |
|
librepo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: e4ab44d712d043ee721bb4a066758101e708bd6cfa0258bd6367eadd20bc02c7 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: 1687b9e3743b4a765912baf9c18d491913b74095420e8a16c3ec392d84aeab45 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: 1687b9e3743b4a765912baf9c18d491913b74095420e8a16c3ec392d84aeab45 |
|
librepo-devel-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: ea0fb52d97728e27d8eab4cc81d9acd312b9fd0245cb0a980bff292d55066046 |
|
python-librepo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: d610db11e16af46c436fc253d3aba8088d5bbd84c0b3f9887c3b9a6e92c1bc14 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| s390x |
|
librepo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 9f0ce6bfbc6a586e540d18043218d838f5785007de3d924b387eb4176055422f |
|
librepo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 8b5a37a3baa8ff8001f1b77993ec1545e4949b852d10604da54d745d0b6c68f3 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 7a0d75bafcaa4f8558348166dded55c04110e9ea56fef6f65b70c20c57409cd5 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 7a0d75bafcaa4f8558348166dded55c04110e9ea56fef6f65b70c20c57409cd5 |
|
librepo-debuginfo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: d877f1f20f4c5d37a231f50cc1a4141d57ed479c5ddadd40047f0f3f32a79bcb |
|
librepo-debuginfo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: d877f1f20f4c5d37a231f50cc1a4141d57ed479c5ddadd40047f0f3f32a79bcb |
|
librepo-devel-1.8.1-8.el7_9.s390.rpm
|
SHA-256: 1389843b7c01a104412f3e607fe71c521623095bce1f4e23da017fae07e2661d |
|
librepo-devel-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 5d192daa3ed176b4622c6ed1e98f2944191586d0ed56ece3e4dacf514cdeaea7 |
|
python-librepo-1.8.1-8.el7_9.s390x.rpm
|
SHA-256: 1cb23cfdd5aee769578d99f23bed83065fec41e9191f7a6e7dbbef8c1d79656f |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| ppc64 |
|
librepo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: 1249f1880a175ce6ef13ea64f9b05936038370ee0cd4aaaa0007d767d8ab3c30 |
|
librepo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 18141f9f9ddd668c93afa037e27d2a68d04af821150565e588ec523bb6e34547 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: bca4e1b206dd845e15f00758babe6d33661f36d75a77d767573742c3eae219cb |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: bca4e1b206dd845e15f00758babe6d33661f36d75a77d767573742c3eae219cb |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: bc41da68812eabb3a666efbc6e2d561fdbe0f318fdfda7327488bf4220c613f1 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: bc41da68812eabb3a666efbc6e2d561fdbe0f318fdfda7327488bf4220c613f1 |
|
librepo-devel-1.8.1-8.el7_9.ppc.rpm
|
SHA-256: 55effabbbaed42b710917a2ecbacbef8e595ea4208632d4ea0ab9cadad0c5dc3 |
|
librepo-devel-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 4ebd2c95cf26e993429ce39789d128a8d09c908e0423d41e5464d16f4788ea97 |
|
python-librepo-1.8.1-8.el7_9.ppc64.rpm
|
SHA-256: 6c9899464089f7f94ea815d8f3ba446a8ffe4e8b074b7eeceed9e76139841872 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
| SRPM |
|
librepo-1.8.1-8.el7_9.src.rpm
|
SHA-256: 6387132b5c8875a93fd08b8cac2ee1e05ddee15ad9530e34fb11366ede6b60c6 |
| ppc64le |
|
librepo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: e4ab44d712d043ee721bb4a066758101e708bd6cfa0258bd6367eadd20bc02c7 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: 1687b9e3743b4a765912baf9c18d491913b74095420e8a16c3ec392d84aeab45 |
|
librepo-debuginfo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: 1687b9e3743b4a765912baf9c18d491913b74095420e8a16c3ec392d84aeab45 |
|
librepo-devel-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: ea0fb52d97728e27d8eab4cc81d9acd312b9fd0245cb0a980bff292d55066046 |
|
python-librepo-1.8.1-8.el7_9.ppc64le.rpm
|
SHA-256: d610db11e16af46c436fc253d3aba8088d5bbd84c0b3f9887c3b9a6e92c1bc14 |