oss-sec mailing list archives
Re: CVE request -- git
From: Sebastian Krahmer <krahmer () suse de>
Date: Tue, 20 Jan 2009 10:11:58 +0100
On Tue, Jan 20, 2009 at 09:02:31AM +0100, Tomas Hoger wrote:
No, they have not. They fixed both -5516 (git_search) and -5517 (git_snapshot and git_object) issues using quote_command() (in their git-1.5.2.4-24.4.src.rpm). No idea why only one of the CVEs was mentioned in the security report... They don't seem to include any patch for diff.external issue, or claim to have fixed it.
Only opensuse 11.0 and 11.1 were affected by diff.external issue and packages have been released for that. opensuse 10.3 was only affected by the remote hole and not by diff.external. packages were already released, too. Sebastian -- ~ ~ perl self.pl ~ $_='print"\$_=\47$_\47;eval"';eval ~ krahmer () suse de - SuSE Security Team ~ SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)
Current thread:
- CVE request -- git Florian Weimer (Jan 15)
- Re: CVE request -- git Florian Weimer (Jan 19)
- Re: CVE request -- git Tomas Hoger (Jan 20)
- Re: CVE request -- git Sebastian Krahmer (Jan 20)
- Re: CVE request -- git Tomas Hoger (Jan 20)
- Re: CVE request -- git Sebastian Krahmer (Jan 20)
- Re: CVE request -- git Tomas Hoger (Jan 20)
- Re: CVE request -- git Florian Weimer (Jan 19)
- Re: CVE request -- git Tomas Hoger (Jan 21)
- Re: CVE request -- git Steven M. Christey (Jan 22)
- Re: CVE request -- git Tomas Hoger (Jan 23)