-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.1483
                         composer security update
                               30 April 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           composer
Publisher:         Debian
Operating System:  Debian GNU/Linux
                   UNIX variants (UNIX, Linux, OSX)
                   Windows
Impact/Access:     Execute Arbitrary Code/Commands -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-29472  

Original Bulletin: 
   https://lists.debian.org/debian-security-announce/2021/msg00088.html

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running composer check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4907-1                   security@debian.org
https://www.debian.org/security/                       Sebastien Delafond
April 29, 2021                        https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : composer
CVE ID         : CVE-2021-29472

It was discovered that composer, a dependency manager for PHP, did not
properly sanitize Mercurial URLs, which could lead to arbitrary code
execution.

For the stable distribution (buster), this problem has been fixed in
version 1.8.4-1+deb10u1.

We recommend that you upgrade your composer packages.

For the detailed security status of composer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/composer

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAmCK4LkACgkQEL6Jg/PV
nWQhBwgArIovQUUooqTS91bHsjuqtP5cXvbbeSbLml9cRug6U83QJEeDOnLz/ljd
K0gZLZIHAi7B9iMX/oeSA73VYmSyfEp1DhSaluGSMkbvzptONDt6j/wKc23Zr/A8
C8/wcD1k4rIC3VmyEWNKtO/qZZ+nt/WX6Fpq4PrlOdhO3ea/hctzlz3UacVoThwD
HSHBHn5pWQygHQYdWva/HNeeEtwE81gBaQ3BYYJ+NWgZilfHW2pU5ilhWi2jur3z
nwgpqIKVhfhC3jG4552n15E5i5T28LR8IXfijtHr91b4Q2ZtVdKQdSYs8UO0+jA8
Lz0xVj6CyVNsrmXe3fMzkIVeIzA04g==
=2MWQ
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYItWhONLKJtyKPYoAQiFog//d958az00uhnM0h846dvcRCIjUn14ic/o
zACVpPjSDMSVwNZ+n9UX2K41KlENriAE0jdax99D+BmXlQaecjirOX4Xse7uMwti
7yLilGyz2VwYMYP+MClNzfy4dPiG4R9pLfIidUMcKEk3iTFoukG/VDCYkRT3BQA2
WUrAcxJWUQ1gLoQCo5pHLYdLjb0EaCKwKBADEe856sYhBDoVqN/eiO7MZITc17Cc
V0g1mPPJE2g4ogMAPMFDUNB9sLs9gVrGq3SODS4xbKq8nrul6Ic+oBqTGdU0AF1U
7T0RSn5Lk4F8CNfHCrq5KuwNXrPAixp2MEGzNZDP4kbgEidAo4YTHfOASPOxSKPs
KhPGBfmCY9/gB5QZENKZ+x+B5BXSX5YykcmlRkeFXHXcoEAlQLtMz+dbstjpODAv
EAEo2GVNGC3iFHZXFjCKBmFSXuBzS5hEnwq+Xyx6wljqqOV54Xa5KDpnxm6Zkuus
hGqyN7dpGvU2VjFLoNvhDCQU/slB5zHYEncrb54lM7Ll9i+X8MZd7abdQD9x3HxQ
chDEXdxCqvn48rIwrUOkZiWuOpBUlDk0YU4ZPu/2Pv+dyJWycpy19/ZhUgig3Hxl
WAVXQeS2QnxDyD4ndVl14V+qaIHJ1Bvl8IFFObyuWcb6i6jWudwjkqZzBh6GiY8I
aCaYrcSUEdw=
=hJG+
-----END PGP SIGNATURE-----