Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 8: DLA-2177-1 Critical: Git Credential Exposure Issue

debian lts
Calendar Grey April 15, 2020
Dist Debian Esm H88
Enhance your Git installation to fix the security flaw related to manipulated URLs in Debian 8 that could expose credentials.

Felix Wilhelm of Google Project Zero discovered a flaw in git, a fast, scalable, distributed revision control system

Summary

Felix Wilhelm of Google Project Zero discovered a flaw in git, a fast,
scalable, distributed revision control system. With a crafted URL that
contains a newline, the credential helper machinery can be fooled to
return credential information for a wrong host.

For Debian 8 "Jessie", this problem has been fixed in version
1:2.1.4-2.1+deb8u9.

We recommend that you upgrade your git packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><span style="font-family: Courier;">Package : git
Version: 1:2.1.4-2.1+deb8u9
CVE ID: CVE-2020-5260

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here