Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 9 MGASA-2025-0016: Critical Git Credential Issues Addressed

mageia
Calendar Grey January 20, 2025
Dist Mageia Esm H88
MGASA-2025-0017 introduces protection patches for vulnerabilities found in ssh, bolstering authorization integrity as of Jan 22, 2025
Git does not sanitize URLs when asking for credentials interactively

Summary

Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006)

References

- https://bugs.mageia.org/show_bug.cgi?id=33921

- https://www.openwall.com/lists/oss-security/2025/01/14/4

- https://www.cve.org/CVERecord?id=CVE-2024-50349

- https://www.cve.org/CVERecord?id=CVE-2024-52006

Resolution

SRPMS

- 9/core/git-2.41.3-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 20 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0016.html
Type: security
CVE: CVE-2024-50349, CVE-2024-52006

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here