Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 36: 2023-2663dc67d8 Moderate: Excessive Memory Growth in Git Auth

fedora
Calendar Grey February 2, 2023
Dist Fedora Esm H88
Implement security patch for Git credential helper in Fedora 36 to resolve significant memory bloat problem.
Rebuild for security fix

Summary

A Git credential helper that authenticates to GitHub, GitLab, BitBucket and

other forges using OAuth. The first time you push, the helper will open a

browser window to authenticate. Subsequent pushes within the cache timeout

require no interaction.

Rebuild for security fix

* Mon Jan 23 2023 M Hickford - 0.1.5-1

- Revert "New upstream version 0.4.1"

* Mon Jan 23 2023 M Hickford - 0.4.1-1

- New upstream version 0.4.1

* Thu Jan 19 2023 Fedora Release Engineering - 0.1.5-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

* Tue Dec 6 2022 M Hickford - 0.1.5-1

- Initial import (fedora#2142391).

[ 1 ] Bug #2163091 - CVE-2022-41717 git-credential-oauth: golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2163091

su -c 'dnf upgrade --advisory FEDORA-2023-2663dc67d8' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Product: Fedora 36
Version: 0.1.5
Release: 1.fc36
Summary: Git credential helper for GitHub and other forges using OAuth

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here