Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE Leap 42.1: 2016:0802-1 Important: Git Buffer Overflow

opensuse
Calendar Grey March 17, 2016
Dist Opensuse Esm H88
An important update resolves major vulnerabilities in git for openSUSE Leap 42.1 and 13.2. Apply the essential fixes to safeguard your system's integrity.
An update that fixes two vulnerabilities is now available.

Description

This update for git fixes a buffer overflow issue that had the potential

to be abused for remote execution of arbitrary code (CVE-2016-2315,

CVE-2016-2324, bsc#971328).

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-355=1

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-355=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

git-2.6.2-3.1

git-arch-2.6.2-3.1

git-core-2.6.2-3.1

git-core-debuginfo-2.6.2-3.1

git-credential-gnome-keyring-2.6.2-3.1

git-credential-gnome-keyring-debuginfo-2.6.2-3.1

git-cvs-2.6.2-3.1

git-daemon-2.6.2-3.1

git-daemon-debuginfo-2.6.2-3.1

git-debugsource-2.6.2-3.1

git-email-2.6.2-3.1

git-gui-2.6.2-3.1

git-svn-2.6.2-3.1

git-svn-debuginfo-2.6.2-3.1

git-web-2.6.2-3.1

gitk-2.6.2-3.1

- openSUSE Leap 42.1 (noarch):

git-doc-2.6.2-3.1

- openSUSE 13.2 (i586 x86_64):

git-2.1.4-19.1

git-arch-2.1.4-19.1

git-core-2.1.4-19.1

git-core-debuginfo-2.1.4-19.1

git-cvs-2.1.4-19.1

git-daemon-2.1.4-19.1

git-daemon-debuginfo-2.1.4-19.1

git-debugsource-2.1.4-19.1

git-email-2.1.4-19.1

git-gui-2.1.4-19.1

git-svn-2.1.4-19.1

git-svn-debuginfo-2.1.4-19.1

git-web-2.1.4-19.1

gitk-2.1.4-19.1

- openSUSE 13.2 (noarch):

git-doc-2.1.4-19.1

References

https://www.suse.com/security/cve/CVE-2016-2315.html

https://www.suse.com/security/cve/CVE-2016-2324.html

https://bugzilla.suse.com/971328

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:0802-1
Rating: important
Affected Products: openSUSE Leap 42.1 openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here