Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE: 2020:0598-1 Moderate: Git Credential Issue Update

opensuse
Calendar Grey May 1, 2020
Dist Opensuse Esm H88
openSUSE releases a security notice for vim addressing 12 vulnerabilities. Crucial warning for users. Prompt updates advised!
An update that solves 15 vulnerabilities and has 8 fixes is now available.

Description

This update for git fixes the following issues:

Security issues fixed:

* CVE-2020-11008: Specially crafted URLs may have tricked the credentials

helper to providing credential information that is not appropriate for

the protocol in use and host being contacted (bsc#1169936)

git was updated to 2.26.1 (bsc#1169786, jsc#ECO-1628, bsc#1149792)

- Fix git-daemon not starting after conversion from sysvinit to systemd

service (bsc#1169605).

* CVE-2020-5260: Specially crafted URLs with newline characters could have

been used to make the Git client to send credential information for a

wrong host to the attacker's site bsc#1168930

git 2.26.0 (bsc#1167890, jsc#SLE-11608):

* "git rebase" now uses a different backend that is based on the 'merge'

machinery by default. The 'rebase.backend' configuration variable

reverts to old behaviour when set to 'apply'

* Improved handling of sparse checkouts

* Improvements to many commands...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-598=1

Package List

- openSUSE Leap 15.1 (x86_64):

git-2.26.1-lp151.4.9.1

git-arch-2.26.1-lp151.4.9.1

git-core-2.26.1-lp151.4.9.1

git-core-debuginfo-2.26.1-lp151.4.9.1

git-credential-gnome-keyring-2.26.1-lp151.4.9.1

git-credential-gnome-keyring-debuginfo-2.26.1-lp151.4.9.1

git-credential-libsecret-2.26.1-lp151.4.9.1

git-credential-libsecret-debuginfo-2.26.1-lp151.4.9.1

git-cvs-2.26.1-lp151.4.9.1

git-daemon-2.26.1-lp151.4.9.1

git-daemon-debuginfo-2.26.1-lp151.4.9.1

git-debuginfo-2.26.1-lp151.4.9.1

git-debugsource-2.26.1-lp151.4.9.1

git-email-2.26.1-lp151.4.9.1

git-gui-2.26.1-lp151.4.9.1

git-p4-2.26.1-lp151.4.9.1

git-svn-2.26.1-lp151.4.9.1

git-svn-debuginfo-2.26.1-lp151.4.9.1

git-web-2.26.1-lp151.4.9.1

gitk-2.26.1-lp151.4.9.1

- openSUSE Leap 15.1 (noarch):

git-doc-2.26.1-lp151.4.9.1

References

https://https://www.suse.com/security/cve/CVE-2017-15298.html

https://www.suse.com/security/cve/CVE-2018-11233.html

https://www.suse.com/security/cve/CVE-2018-11235.html

https://www.suse.com/security/cve/CVE-2018-17456.html

https://www.suse.com/security/cve/CVE-2019-1348.html

https://www.suse.com/security/cve/CVE-2019-1349.html

https://www.suse.com/security/cve/CVE-2019-1350.html

https://www.suse.com/security/cve/CVE-2019-1351.html

https://www.suse.com/security/cve/CVE-2019-1352.html

https://www.suse.com/security/cve/CVE-2019-1353.html

https://www.suse.com/security/cve/CVE-2019-1354.html

https://www.suse.com/security/cve/CVE-2019-1387.html

https://www.suse.com/security/cve/CVE-2019-19604.html

https://www.suse.com/security/cve/CVE-2020-11008.html

https://www.suse.com/security/cve/CVE-2020-5260.html

https://bugzilla.suse.com/1063412

https://bugzilla.suse.com/1095218

https://bugzilla.suse.com/1095219

https://bugzilla.suse.com/1110949

https://bugzilla.suse.com/1112230

https://bugzilla.suse.com/1114225

https://...

Read the Full Advisory

Announcement ID: openSUSE-SU-2020:0598-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here