Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2016:0798-1 Critical: Git Remote Execution Threat

suse
Calendar Grey March 17, 2016
Dist Suse Esm H88
SUSE has released a Security Update for git, addressing critical buffer overflow vulnerabilities in its offerings, with detailed guidance for patch implementation
An update that fixes two vulnerabilities is now available

Summary

This update for git fixes a buffer overflow issue that had the potential to be abused for remote execution of arbitrary code (CVE-2016-2315, CVE-2016-2324, bsc#971328). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-git-12460=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-git-12460=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-git-12460=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): git-core-1.7.12.4-0.14.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): git-1.7.12.4-0.14.1

References

#971328

Cross- CVE-2016-2315 CVE-2016-2324

Affected Products:

SUSE OpenStack Cloud 5

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-2315.html

https://www.suse.com/security/cve/CVE-2016-2324.html

https://bugzilla.suse.com/971328

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0798-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here