--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2025-c7b9b07dd3
2025-12-03 00:40:11.755987+00:00
--------------------------------------------------------------------------------

Name        : rclone
Product     : Fedora EPEL 10.2
Version     : 1.72.0
Release     : 1.el10_2
URL         : https://github.com/rclone/rclone
Summary     : Rsync for cloud storage
Description :
"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive,
Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex
Files.

--------------------------------------------------------------------------------
Update Information:

Update to 1.72.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Nov 24 2025 Mikel Olasagasti Uranga <[email protected]> - 1.72.0-1
- Update to 1.72.0 - Closes rhbz#2397899
* Fri Oct 10 2025 Alejandro Sáez <[email protected]> - 1.71.0-2
- rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2398309 - CVE-2025-47910 rclone: CrossOriginProtection bypass in 
net/http [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398309
  [ 2 ] Bug #2398947 - CVE-2025-47906 rclone: Unexpected paths returned from 
LookPath in os/exec [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398947
  [ 3 ] Bug #2407494 - CVE-2025-58189 rclone: go crypto/tls ALPN negotiation 
error contains attacker controlled information [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407494
  [ 4 ] Bug #2408534 - CVE-2025-61725 rclone: Excessive CPU consumption in 
ParseAddress in net/mail [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408534
  [ 5 ] Bug #2408946 - CVE-2025-61723 rclone: Quadratic complexity when parsing 
some invalid inputs in encoding/pem [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408946
  [ 6 ] Bug #2409888 - CVE-2025-58185 rclone: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409888
  [ 7 ] Bug #2410828 - CVE-2025-58188 rclone: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410828
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update rclone' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to