Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Mageia: 2020-0175 Critical: Git Malicious URL Security Update

mageia
Calendar Grey April 16, 2020
Dist Mageia Esm H88
MGASA-2020-0176 addresses the vulnerability in SSH, mitigating risks from exploitative code fragments. Important security patch released.

With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host

Summary

With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol (CVE-2020-5260).

References

- https://bugs.mageia.org/show_bug.cgi?id=26483

- https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q

- https://www.cve.org/CVERecord?id=CVE-2020-5260

Resolution

SRPMS

- 7/core/git-2.21.2-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 16 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0175.html
Type: security
CVE: CVE-2020-5260

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here