Git LFS permits exfiltration of credentials via crafted HTTP URLs. (CVE-2024-53263) References: - https://bugs.mageia.org/show_bug.cgi?id=33931 . MGASA-2025-0028 - Updated git-lfs packages fix security vulnerability Publication date: 30 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0028.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-53263 Git LFS permits exfiltration of credentials via crafted HTTP URLs. (CVE-2024-53263) References: - https://bugs.mageia.org/show_bug.cgi?id=33931 - - https://lists.debian.org/debian-security-announce/2025/msg00011.html - https://www.cve.org/CVERecord?id=CVE-2024-53263 SRPMS: - 9/core/git-lfs-3.2.0-1.1.mga9 . Latest Mageia git-lfs updates address severe security vulnerability that could lead to credential compromise through specially designed HTTP links.. git-lfs security, Mageia advisory, credential theft, Linux updates. . Severity: Critical. LinuxSecurity.com Team
Update to latest version Fix CVE-2024-53263. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-50deb0acd5 2025-01-24 01:31:27.317862+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 40 Version : 3.6.1 Release : 1.fc40 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version Fix CVE-2024-53263 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Elliott Sales de Andrade - 3.6.1-1 - Update to latest version (#2338023) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2338002 - CVE-2024-53263 git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs https://bugzilla.redhat.com/show_bug.cgi?id=2338002 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-50deb0acd5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Update to latest version Fix CVE-2024-53263. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1de066b8af 2025-01-24 01:24:33.421855+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 41 Version : 3.6.1 Release : 1.fc41 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version Fix CVE-2024-53263 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Elliott Sales de Andrade - 3.6.1-1 - Update to latest version (#2338023) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2338002 - CVE-2024-53263 git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs https://bugzilla.redhat.com/show_bug.cgi?id=2338002 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1de066b8af' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006) . MGASA-2025-0016 - Updated git packages fix security vulnerabilities Publication date: 20 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0016.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-50349, CVE-2024-52006 Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006) References: - https://bugs.mageia.org/show_bug.cgi?id=33921 - https://www.openwall.com/lists/oss-security/2025/01/14/4 - https://www.cve.org/CVERecord?id=CVE-2024-50349 - https://www.cve.org/CVERecord?id=CVE-2024-52006 SRPMS: - 9/core/git-2.41.3-1.mga9 . MGASA-2025-0017 introduces protection patches for vulnerabilities found in ssh, bolstering authorization integrity as of Jan 22, 2025. credential exfiltration, git updates, Mageia advisory, security updates, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.