Mageia alert MGASA-2025-0016 (git)
From: | Mageia Updates <updates-announce@ml.mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2025-0016: Updated git packages fix security vulnerabilities | |
Date: | Mon, 20 Jan 2025 19:22:23 +0100 | |
Message-ID: | <20250120182223.6C50DA0DAD@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2025-0016 - Updated git packages fix security vulnerabilities Publication date: 20 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0016.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-50349, CVE-2024-52006 Description: Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006) References: - https://bugs.mageia.org/show_bug.cgi?id=33921 - https://www.openwall.com/lists/oss-security/2025/01/14/4 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... SRPMS: - 9/core/git-2.41.3-1.mga9