{"affected":[],"aliases":[],"details":"This update for obs-service-tar_scm fixes the following issues:\n\nSecurity vulnerabilities addressed:\n\n- CVE-2018-12473: Fixed a path traversal issue, which allowed users to access\n  files outside of the repository using relative paths (bsc#1105361)\n- CVE-2018-12474: Fixed an issue whereby crafted service parameters allowed for\n  unexpected behaviour (bsc#1107507)\n- CVE-2018-12476: Fixed an issue whereby the outfilename parameter allowed to\n  write files outside of package directory (bsc#1107944)\n\nOther bug fixes and changes made:\n\n- Prefer UTF-8 locale as output format for changes\n- added KankuFile\n- fix problems with unicode source files\n- added python-six to Requires in specfile\n- better encoding handling\n- fixes bsc#1082696 and bsc#1076410\n- fix unicode in containers\n- move to python3\n- added logging for better debugging changesgenerate\n- raise exception if no changesauthor given\n- Stop using @opensuse.org addresses to indicate a missing address\n- move argparse dep to -common package\n- allow submodule and ssl options in appimage\n- sync spec file as used in openSUSE:Tools project\n- check encoding problems for svn and print proper error msg\n- added new param '--locale'\n- separate service file installation in GNUmakefile\n- added glibc as Recommends in spec file\n- cleanup for broken svn caches\n- another fix for unicode problem in obs_scm\n- Final fix for unicode in filenames\n- Another attempt to fix unicode filenames in prep_tree_for_archive\n- Another attempt to fix unicode filenames in prep_tree_for_archive\n- fix bug with unicode filenames in prep_tree_for_archive\n- reuse _service*_servicedata/changes files from previous service runs\n- fix problems with  unicode characters in commit messages for changeloggenerate\n- fix encoding issues if commit message contains utf8 char\n- revert encoding for old changes file\n- remove hardcoded utf-8 encodings\n- Add support for extract globbing\n- split pylint2 in GNUmakefile\n- fix check for '--reproducible'\n- create reproducible obscpio archives\n- fix regression from 44b3bee\n- Support also SSH urls for Git\n- check name/version option in obsinfo for slashes\n- check url for remote url\n- check symlinks in subdir parameter\n- check filename for slashes\n- disable follow_symlinks in extract feature\n- switch to obs_scm for this package\n- run download_files in appimage and snapcraft case\n- check --extract file path for parent dir\n- Fix parameter descriptions\n- changed os.removedirs -> shutil.rmtree\n- Adding information regarding the *package-metadata* option for the *tar* service The tar service is highly useful in combination with the *obscpio* service. After the fix for the metadata for the latter one, it is important to inform the users of the *tar* service that metadata is kept only if the flag *package-metadata* is enabled. Add the flag to the .service file for mentioning that.\n- Allow metadata packing for CPIO archives when desired As of now, metadata are always excluded from *obscpio* packages. This is because the *package-metadata* flag is ignored; this change (should) make *obscpio* aware of it.\n- improve handling of corrupt git cache directories\n- only do git stash save/pop if we have a non-empty working tree (#228)\n- don't allow DEBUG_TAR_SCM to change behaviour (#240)\n- add stub user docs in lieu of something proper (#238)\n- Remove clone_dir if clone fails\n- python-unittest2 is only required for the optional make check\n- move python-unittest2 dep to test suite only part (submission by olh)\n- Removing redundant pass statement\n- missing import for logging functions.\n- [backend] Adding http proxy support\n- python-unittest2 is only required for the optional make check\n- make installation of scm's optional\n- add a lot more detail to README\n- Git clone with --no-checkout in prepare_working_copy\n- Refactor and simplify git prepare_working_copy\n- Only use current dir if it actually looks like git (Fixes #202)\n- reactivate test_obscpio_extract_d\n- fix broken test create_archive\n- fix broken tests for broken-links\n- changed PREFIX in Gnumakefile to /usr\n- new cli option --skip-cleanup\n- fix for broken links\n- fix reference to snapcraft YAML file\n- fix docstring typo in TarSCM.scm.tar.fetch_upstream\n- acknowledge deficiencies in dev docs\n- wrap long lines in README\n","id":"SUSE-SU-2019:0540-1","modified":"2019-03-04T16:42:47Z","published":"2019-03-04T16:42:47Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20190540-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1076410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082696"},{"type":"REPORT","url":"https://bugzilla.suse.com/1105361"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107944"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12474"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12476"}],"related":["CVE-2018-12473","CVE-2018-12474","CVE-2018-12476"],"summary":"Security update for obs-service-tar_scm","upstream":["CVE-2018-12473","CVE-2018-12474","CVE-2018-12476"]}