Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Slackware: 2020-112-01 Moderate: Git Credential Management Issue

slackware
Calendar Grey April 21, 2020
Dist Slackware Esm H88
Updated Git distributions for Slackware 14 address vulnerabilities related to credential management, enhancing user data security.
New git packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/git-2.17.5-i586-1_slack14.2.txz: Upgraded. This update fixes a security issue: With a crafted URL that contains a newline or empty host, or lacks a scheme, the credential helper machinery can be fooled into providing credential information that is not appropriate for the protocol in use and host being contacted. Unlike the vulnerability CVE-2020-5260 fixed in v2.17.4, the credentials are not for a host of the attacker's choosing; instead, they are for some unspecified host (based on how the configured credential helper handles an absent "host" parameter). For more information, see: https://www.cve.org/CVERecord?id=CVE-2020-11008 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: 558c3fb44c4b314f7da5c3c807eeecc0 git-2.17.5-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: bea3f89056978279971e2c5a98321459 git-2.17.5-x86_64-1_slack14.0.txz
Slackware 14.1 package: 35ca91631aa102f23a8ceac0ace0d574 git-2.17.5-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 0a75156767ea9ff4f0e9d5f965527f52 git-2.17.5-x86_64-1_slack14.1.txz
Slackware 14.2 package: ca39eba5ffe65eef6151f5118c7da317 git-2.17.5-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: 516cf56c833774225eb352c7d1ab0392 git-2.17.5-x86_64-1_slack14.2.txz
Slackware -current package: 450a483052c7b3e779bb0519fbb02638 d/git-2.26.2-i586-1.txz
Slackware x86_64 -current package: 08382f2cb3766063aadabf3c3d36c602 d/git-2.26.2-x86_64-1.txz

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg git-2.17.5-i586-1_slack14.2.txz

Related News

Your message here