Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2020:1121-1 Moderate: Git Security Update Details

suse
Calendar Grey April 28, 2020
Dist Suse Esm H88
SUSE has issued a Security Update addressing 12 vulnerabilities in samba, bolstering defenses against unauthorized access and system instability.
An update that solves 15 vulnerabilities and has 8 fixes is now available

Summary

This update for git fixes the following issues: Security issues fixed: * CVE-2020-11008: Specially crafted URLs may have tricked the credentials helper to providing credential information that is not appropriate for the protocol in use and host being contacted (bsc#1169936) git was updated to 2.26.1 (bsc#1169786, jsc#ECO-1628, bsc#1149792) - Fix git-daemon not starting after conversion from sysvinit to systemd service (bsc#1169605). * CVE-2020-5260: Specially crafted URLs with newline characters could have been used to make the Git client to send credential information for a wrong host to the attacker's site bsc#1168930 git 2.26.0 (bsc#1167890, jsc#SLE-11608): * "git rebase" now uses a different backend that is based on the 'merge' machinery by default. The 'rebase.backend' configuration variable

References

#1063412 #1095218 #1095219 #1110949 #1112230

#1114225 #1132350 #1149792 #1156651 #1158785

#1158787 #1158788 #1158789 #1158790 #1158791

#1158792 #1158793 #1158795 #1167890 #1168930

#1169605 #1169786 #1169936

Cross- CVE-2017-15298 CVE-2018-11233 CVE-2018-11235

CVE-2018-17456 CVE-2019-1348 CVE-2019-1349

CVE-2019-1350 CVE-2019-1351 CVE-2019-1352

CVE-2019-1353 CVE-2019-1354 CVE-2019-1387

CVE-2019-19604 CVE-2020-11008 CVE-2020-5260

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Development Tools 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2017-15298.html

https://www.suse.com/security/cve/CVE-2018-11233.html

Announcement ID: SUSE-SU-2020:1121-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here