Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-6050-2 May 17, 2023 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-6050-1 fixed several vulnerabilities in Git. This update provides the corresponding updates for CVE-2023-25652 and CVE-2023-29007 on Ubuntu 16.04 LTS. Original advisory details: It was discovered that Git incorrectly handled certain commands. An attacker could possibly use this issue to overwrite paths. (CVE-2023-25652) André Baptista and Vítor Pinho discovered that Git incorrectly handled certain configurations. An attacker could possibly use this issue to achieve arbitrary configuration injection. (CVE-2023-29007) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): git 1:2.7.4-0ubuntu1.10+esm7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6050-2 https://ubuntu.com/security/notices/USN-6050-1 CVE-2023-25652, CVE-2023-29007 . Several vulnerabilities in Git have been resolved in Ubuntu 16.04 LTS, tackling concerns related to path overwriting and potential configuration injection.. Git Security Issues, Ubuntu 16.04 LTS, Path Overwrite Fix. . Severity: Critical. LinuxSecurity.com Team
Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://raw.githubusercontent.com/git/git/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-2b3acb6cfd 2023-02-22 11:06:32.700077 --------------------------------------------------------------------------------Name : git Product : Fedora 36 Version : 2.39.2 Release : 1.fc36 URL : https://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The git rpm installs common set of tools which are usually using with small amount of dependencies. To install all git packages, including tools for integrating with other SCMs, install the git-all meta-package. --------------------------------------------------------------------------------Update Information: Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://raw.githubusercontent.com/git/git/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q), [CVE-2023-23946]() for details. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 14 2023 Todd Zullinger - 2.39.2-1 - update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) * Fri Feb 3 2023 Todd Zullinger - 2.39.1-2 - drop perl Email::Valid dep on RHEL (#2166718) * Thu Jan 19 2023 Fedora Release Engineering - 2.39.1-1.1 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2168160 - CVE-2023-22490 git: data exfiltration with maliciously crafted repository https://bugzilla.redhat.com/show_bug.cgi?id=2168160 [ 2 ] Bug #2168161 - CVE-2023-23946 git: git apply: a path outside the working tree can be overwritten with crafted input https://bugzilla.redhat.com/show_bug.cgi?id=2168161 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2b3acb6cfd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0043-1 Rating: important References: #1149792 #1159352 Cross-References: CVE-2019-16775 CVE-2019-16776 CVE-2019-16777 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP1 SUSE Linux Enterprise Module for Web Scripting 15 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs8 to version 8.17.0 fixes the following issues: Security issues fixed: - CVE-2019-16777, CVE-2019-16776, CVE-2019-16775: Updated npm to 6.13.4, fixing an arbitrary path overwrite and access via "bin" field (bsc#1159352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP1: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP1-2020-43=1 - SUSE Linux Enterprise Module for Web Scripting 15: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-2020-43=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (noarch): nodejs8-docs-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (noarch): nodejs8-docs-8.17.0-3.25.1 References: https://www.suse.com/security/cve/CVE-2019-16775.html https://www.suse.com/security/cve/CVE-2019-16776.html https://www.suse.com/security/cve/CVE-2019-16777.html https://bugzilla.suse.com/1149792 https://bugzilla.suse.com/1159352 _______________________________________________ sle-security-updates mailing list
Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-4220-1 December 10, 2019 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: Joern Schneeweisz and Nicolas Joly discovered that Git contained various security flaws. An attacker could possibly use these issues to overwrite arbitrary paths, execute arbitrary code, and overwrite files in the .git directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: git 1:2.20.1-2ubuntu1.19.10.1 Ubuntu 19.04: git 1:2.20.1-2ubuntu1.19.04.1 Ubuntu 18.04 LTS: git 1:2.17.1-1ubuntu0.5 Ubuntu 16.04 LTS: git 1:2.7.4-0ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4220-1 CVE-2019-1348, CVE-2019-1349, CVE-2019-1350, CVE-2019-1351, CVE-2019-1352, CVE-2019-1353, CVE-2019-1354, CVE-2019-1387, CVE-2019-19604 Package Information: https://launchpad.net/ubuntu/+source/git/1:2.20.1-2ubuntu1.19.04.1 https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.5 https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.7 . Several Git security flaws have been addressed in Ubuntu 19.10 and earlier iterations. Ensure your system is updated for enhanced security.. Git Security Issues, Ubuntu Git Update, Software Fixes, System Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.