Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia: 2025-0028 critical: git-lfs credential exfiltration

Git LFS permits exfiltration of credentials via crafted HTTP URLs. (CVE-2024-53263) References: - https://bugs.mageia.org/show_bug.cgi?id=33931 . MGASA-2025-0028 - Updated git-lfs packages fix security vulnerability Publication date: 30 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0028.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-53263 Git LFS permits exfiltration of credentials via crafted HTTP URLs. (CVE-2024-53263) References: - https://bugs.mageia.org/show_bug.cgi?id=33931 - - https://lists.debian.org/debian-security-announce/2025/msg00011.html - https://www.cve.org/CVERecord?id=CVE-2024-53263 SRPMS: - 9/core/git-lfs-3.2.0-1.1.mga9 . Latest Mageia git-lfs updates address severe security vulnerability that could lead to credential compromise through specially designed HTTP links.. git-lfs security, Mageia advisory, credential theft, Linux updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 30, 2025 Critical Mageia
89

Fedora 40 Update: Critical Fix for git-lfs Credential Theft Issue in 2025

Update to latest version Fix CVE-2024-53263. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-50deb0acd5 2025-01-24 01:31:27.317862+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 40 Version : 3.6.1 Release : 1.fc40 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version Fix CVE-2024-53263 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Elliott Sales de Andrade - 3.6.1-1 - Update to latest version (#2338023) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2338002 - CVE-2024-53263 git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs https://bugzilla.redhat.com/show_bug.cgi?id=2338002 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-50deb0acd5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The latest git-lfs update in Fedora 40 mitigates CVE-2024-53263, enhancing security by stopping the unauthorized access of credentials.. Fedora 40, git-lfs update, credential management, security patch, open source security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2025 Critical Fedora
89

Fedora 41: git-lfs 2025-1de066b8af critical: credential exfiltration

Update to latest version Fix CVE-2024-53263. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1de066b8af 2025-01-24 01:24:33.421855+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 41 Version : 3.6.1 Release : 1.fc41 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version Fix CVE-2024-53263 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Elliott Sales de Andrade - 3.6.1-1 - Update to latest version (#2338023) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2338002 - CVE-2024-53263 git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs https://bugzilla.redhat.com/show_bug.cgi?id=2338002 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1de066b8af' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The git-lfs version 3.6.1 update in Fedora 41 resolves a significant vulnerability related to credential leakage.. git-lfs update, Fedora security patch, credential exfiltration, Linux update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2025 Critical Fedora
203

Mageia 9 MGASA-2025-0016: Critical Git Credential Issues Addressed

Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006) . MGASA-2025-0016 - Updated git packages fix security vulnerabilities Publication date: 20 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0016.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-50349, CVE-2024-52006 Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006) References: - https://bugs.mageia.org/show_bug.cgi?id=33921 - https://www.openwall.com/lists/oss-security/2025/01/14/4 - https://www.cve.org/CVERecord?id=CVE-2024-50349 - https://www.cve.org/CVERecord?id=CVE-2024-52006 SRPMS: - 9/core/git-2.41.3-1.mga9 . MGASA-2025-0017 introduces protection patches for vulnerabilities found in ssh, bolstering authorization integrity as of Jan 22, 2025. credential exfiltration, git updates, Mageia advisory, security updates, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 20, 2025 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here