Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

git: security update to 2.23.1/2.24.1 #2059

Closed
1 of 8 tasks
l2dy opened this issue Dec 11, 2019 · 2 comments
Closed
1 of 8 tasks

git: security update to 2.23.1/2.24.1 #2059

l2dy opened this issue Dec 11, 2019 · 2 comments
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@l2dy
Copy link
Member

l2dy commented Dec 11, 2019

CVE IDs: CVE-2019-1348, CVE-2019-1349, CVE-2019-1350, CVE-2019-1351, CVE-2019-1352, CVE-2019-1353, CVE-2019-1354, CVE-2019-1387, CVE-2019-19604

Other security advisory IDs: USN-4220-1, DSA-4581-1

Descriptions:
Joern Schneeweisz and Nicolas Joly discovered that Git contained various
security flaws. An attacker could possibly use these issues to overwrite
arbitrary paths, execute arbitrary code, and overwrite files in the .git
directory.

Patches: N/A

PoC(s): N/A

Architectural progress (Stable-Proposed, 2.23.1):

  • AMD64 amd64
  • AArch64 arm64
  • ARMv7 armel
  • PowerPC 64-bit BE ppc64

Architectural progress (Testing-Proposed, 2.24.1):

  • AMD64 amd64
  • AArch64 arm64
  • ARMv7 armel
  • PowerPC 64-bit BE ppc64
@l2dy l2dy added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed to-stable labels Dec 11, 2019
@MingcongBai MingcongBai changed the title git: security update to 2.24.1 git: security update to 2.23.1/2.24.1 Dec 11, 2019
@MingcongBai
Copy link
Member

  • For stable-propsoed, update to 2.23.1.
  • For testing-proposed, update to 2.24.1.

@MingcongBai
Copy link
Member

Superseded by #2128. Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

2 participants