From 8a602521ff0d7d8c7090b20e7480782bad3418cb Mon Sep 17 00:00:00 2001 From: Thomas Deutschmann Date: Thu, 23 Apr 2020 17:17:46 +0200 Subject: [ GLSA 202004-13 ] Git: Information disclosure Signed-off-by: Thomas Deutschmann --- glsa-202004-13.xml | 78 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 78 insertions(+) create mode 100644 glsa-202004-13.xml (limited to 'glsa-202004-13.xml') diff --git a/glsa-202004-13.xml b/glsa-202004-13.xml new file mode 100644 index 00000000..35827af3 --- /dev/null +++ b/glsa-202004-13.xml @@ -0,0 +1,78 @@ + + + + Git: Information disclosure + Multiple vulnerabilities have been found in Git which might all + allow attackers to access sensitive information. + + git + 2020-04-23 + 2020-04-23 + 717156 + 718710 + remote + + + 2.23.3 + 2.24.3 + 2.25.4 + 2.26.2 + 2.26.2 + + + +

Git is a free and open source distributed version control system + designed to handle everything from small to very large projects with + speed and efficiency. +

+
+ +

Multiple vulnerabilities have been discovered in Git. Please review the + CVE identifiers referenced below for details. +

+
+ +

A remote attacker, by providing a specially crafted URL, could possibly + trick Git into returning credential information for a wrong host. +

+
+ +

Disabling credential helpers will prevent this vulnerability.

+
+ +

All Git 2.23.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-vcs/git-2.23.3" + + +

All Git 2.24.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-vcs/git-2.24.3" + + +

All Git 2.25.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-vcs/git-2.25.4" + + +

All Git 2.26.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-vcs/git-2.26.2" + + +
+ + CVE-2020-11008 + CVE-2020-5260 + + whissi + whissi +
-- cgit v1.2.3-65-gdbad