oss-sec mailing list archives

Re: CVE request -- git


From: Tomas Hoger <thoger () redhat com>
Date: Tue, 20 Jan 2009 10:31:58 +0100

On Tue, 20 Jan 2009 10:11:58 +0100 Sebastian Krahmer <krahmer () suse de>
wrote:

No, they have not.  They fixed both -5516 (git_search) and -5517
(git_snapshot and git_object) issues using quote_command() (in their
git-1.5.2.4-24.4.src.rpm).  No idea why only one of the CVEs was
mentioned in the security report...  They don't seem to include any
patch for diff.external issue, or claim to have fixed it.

Only opensuse 11.0 and 11.1 were affected by diff.external
issue and packages have been released for that.

SUSE-SR:2009:001 only mentions fix for 10.3.  I probably missed other
report mentioning fixes in 11.x.

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: