This update for git fixes the following issues: Security issues fixed: * CVE-2020-11008: Specially crafted URLs may have tricked the credentials helper to providing credential information that is not appropriate for the protocol in use and host being contacted (bsc#1169936) git was updated to 2.26.1 (bsc#1169786, jsc#ECO-1628, bsc#1149792) - Fix git-daemon not starting after conversion from sysvinit to systemd service (bsc#1169605). * CVE-2020-5260: Specially crafted URLs with newline characters could have been used to make the Git client to send credential information for a wrong host to the attacker's site bsc#1168930 git 2.26.0 (bsc#1167890, jsc#SLE-11608): * "git rebase" now uses a different backend that is based on the 'merge' machinery by default. The 'rebase.backend' configuration variable
#1063412 #1095218 #1095219 #1110949 #1112230
#1114225 #1132350 #1149792 #1156651 #1158785
#1158787 #1158788 #1158789 #1158790 #1158791
#1158792 #1158793 #1158795 #1167890 #1168930
#1169605 #1169786 #1169936
Cross- CVE-2017-15298 CVE-2018-11233 CVE-2018-11235
CVE-2018-17456 CVE-2019-1348 CVE-2019-1349
CVE-2019-1350 CVE-2019-1351 CVE-2019-1352
CVE-2019-1353 CVE-2019-1354 CVE-2019-1387
CVE-2019-19604 CVE-2020-11008 CVE-2020-5260
Affected Products:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
SUSE Linux Enterprise Module for Development Tools 15-SP1
SUSE Linux Enterprise Module for Basesystem 15-SP1
https://www.suse.com/security/cve/CVE-2017-15298.html
https://www.suse.com/security/cve/CVE-2018-11233.html
Get the latest Linux and open source security news straight to your inbox.