Summary: | <dev-vcs/git-{2.23.3,2.24.3,2.25.4}: Crafted URL could leak credential information (CVE-2020-11008) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | polynomial-c, robbat2 |
Priority: | Normal | Keywords: | CC-ARCHES |
Version: | unspecified | Flags: | nattka:
sanity-check+
|
Hardware: | All | ||
OS: | Linux | ||
URL: | https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.17.5.txt | ||
Whiteboard: | A4 [glsa+ cve] | ||
Package list: |
=dev-vcs/git-2.23.3 amd64 arm arm64 hppa ppc ppc64 s390 sparc x86
=dev-vcs/git-2.24.3 amd64 arm arm64 hppa ppc ppc64 s390 sparc x86
=dev-vcs/git-2.25.4 amd64 arm arm64 hppa ppc ppc64 s390 sparc x86
=dev-vcs/git-2.26.2 amd64 arm arm64 hppa ppc ppc64 s390 sparc x86
|
Runtime testing required: | --- |
Description
Sam James
2020-04-21 08:04:49 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=63f418f2391e7cb6048b25c39af0cbb6d2a66947 commit 63f418f2391e7cb6048b25c39af0cbb6d2a66947 Author: Lars Wendler <polynomial-c@gentoo.org> AuthorDate: 2020-04-21 08:23:09 +0000 Commit: Lars Wendler <polynomial-c@gentoo.org> CommitDate: 2020-04-21 08:24:40 +0000 dev-vcs/git: Security bump to ver 2.23.4, 2.24.3, 2.25.4 and 2.26.2 Bug: https://bugs.gentoo.org/718710 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org> dev-vcs/git/Manifest | 12 + dev-vcs/git/git-2.23.3.ebuild | 725 +++++++++++++++++++++++++++++++++++++++++ dev-vcs/git/git-2.24.3.ebuild | 728 ++++++++++++++++++++++++++++++++++++++++++ dev-vcs/git/git-2.25.4.ebuild | 728 ++++++++++++++++++++++++++++++++++++++++++ dev-vcs/git/git-2.26.2.ebuild | 728 ++++++++++++++++++++++++++++++++++++++++++ 5 files changed, 2921 insertions(+) Unable to check for sanity:
> no match for package: =dev-vcs/git-2.23.4
arm64 stable amd64 stable arm stable ppc stable ppc64 stable s390 stable sparc stable x86 stable New GLSA request filed. This issue was resolved and addressed in GLSA 202004-13 at https://security.gentoo.org/glsa/202004-13 by GLSA coordinator Thomas Deutschmann (whissi). Re-opening for remaining architectures. hppa stable @maintainer(s), please cleanup The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6177833229b03609d2a0073c4839a208dec18f5c commit 6177833229b03609d2a0073c4839a208dec18f5c Author: Lars Wendler <polynomial-c@gentoo.org> AuthorDate: 2020-04-29 08:38:35 +0000 Commit: Lars Wendler <polynomial-c@gentoo.org> CommitDate: 2020-04-29 08:38:53 +0000 dev-vcs/git: Security cleanup Bug: https://bugs.gentoo.org/718710 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Lars Wendler <polynomial-c@gentoo.org> dev-vcs/git/Manifest | 27 -- dev-vcs/git/git-2.23.1-r1.ebuild | 725 -------------------------------------- dev-vcs/git/git-2.23.2.ebuild | 725 -------------------------------------- dev-vcs/git/git-2.24.1.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.24.2.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.25.1.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.25.2.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.25.3.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.26.0.ebuild | 728 --------------------------------------- dev-vcs/git/git-2.26.1.ebuild | 728 --------------------------------------- 10 files changed, 6573 deletions(-) |