Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2005-4900 (GCVE-0-2005-4900)
Vulnerability from cvelistv5
Published
2016-10-14 16:00
Modified
2024-08-08 00:01
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-08T00:01:23.514Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://sites.google.com/site/itstheshappening" }, { "name": "12577", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/12577" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://shattered.io/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "http://ia.cr/2007/474" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2005-02-15T00:00:00", "descriptions": [ { "lang": "en", "value": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2020-12-09T08:06:17", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://sites.google.com/site/itstheshappening" }, { "name": "12577", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/12577" }, { "tags": [ "x_refsource_MISC" ], "url": "http://shattered.io/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "tags": [ "x_refsource_MISC" ], "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "tags": [ "x_refsource_MISC" ], "url": "http://ia.cr/2007/474" }, { "tags": [ "x_refsource_MISC" ], "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "tags": [ "x_refsource_MISC" ], "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2005-4900", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://sites.google.com/site/itstheshappening", "refsource": "MISC", "url": "https://sites.google.com/site/itstheshappening" }, { "name": "12577", "refsource": "BID", "url": "http://www.securityfocus.com/bid/12577" }, { "name": "http://shattered.io/", "refsource": "MISC", "url": "http://shattered.io/" }, { "name": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html", "refsource": "MISC", "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "name": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1", "refsource": "MISC", "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "name": "http://ia.cr/2007/474", "refsource": "MISC", "url": "http://ia.cr/2007/474" }, { "name": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html", "refsource": "MISC", "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "name": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html", "refsource": "MISC", "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "name": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html", "refsource": "MISC", "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "name": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/", "refsource": "MISC", "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "name": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340", "refsource": "CONFIRM", "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2005-4900", "datePublished": "2016-10-14T16:00:00", "dateReserved": "2016-10-14T00:00:00", "dateUpdated": "2024-08-08T00:01:23.514Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2005-4900\",\"sourceIdentifier\":\"cve@mitre.org\",\"published\":\"2016-10-14T16:59:00.187\",\"lastModified\":\"2025-04-12T10:46:40.837\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.\"},{\"lang\":\"es\",\"value\":\"SHA-1 no es resistente a la colisi\u00f3n, lo que facilita a atacantes dependientes del contexto llevar a cabo ataques de espionaje, como es demostrado por ataques en el uso de SHA-1 en TLS 1.2. NOTA: esta CVE existe para dar un identificador com\u00fan para referenciar este problema de SHA-1; la existencia de un identificador no es, en si misma, una recomendaci\u00f3n tecnol\u00f3gica.\"}],\"metrics\":{\"cvssMetricV30\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.0\",\"vectorString\":\"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N\",\"baseScore\":5.9,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"HIGH\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":2.2,\"impactScore\":3.6}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:N/C:P/I:N/A:N\",\"baseScore\":4.3,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":8.6,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-326\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*\",\"versionEndIncluding\":\"47.0.2526.111\",\"matchCriteriaId\":\"AFB52550-C3FC-4CDD-AA6E-500BD3304241\"}]}]}],\"references\":[{\"url\":\"http://ia.cr/2007/474\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://shattered.io/\",\"source\":\"cve@mitre.org\"},{\"url\":\"http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1\",\"source\":\"cve@mitre.org\"},{\"url\":\"http://www.securityfocus.com/bid/12577\",\"source\":\"cve@mitre.org\"},{\"url\":\"https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/\",\"source\":\"cve@mitre.org\"},{\"url\":\"https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340\",\"source\":\"cve@mitre.org\"},{\"url\":\"https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html\",\"source\":\"cve@mitre.org\"},{\"url\":\"https://sites.google.com/site/itstheshappening\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.schneier.com/blog/archives/2005/02/sha1_broken.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://ia.cr/2007/474\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://shattered.io/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.securityfocus.com/bid/12577\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://sites.google.com/site/itstheshappening\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.schneier.com/blog/archives/2005/02/sha1_broken.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}],\"evaluatorComment\":\"SHA-1 is likely present in a large number of products across the entire IT sector. The applicability statement for this CVE will be updated when specific products are identified, as time and resources permit.\"}}" } }
fkie_cve-2005-4900
Vulnerability from fkie_nvd
Published
2016-10-14 16:59
Modified
2025-04-12 10:46
Severity ?
Summary
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
References
▶ | URL | Tags | |
---|---|---|---|
cve@mitre.org | http://ia.cr/2007/474 | Third Party Advisory | |
cve@mitre.org | http://shattered.io/ | ||
cve@mitre.org | http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1 | ||
cve@mitre.org | http://www.securityfocus.com/bid/12577 | ||
cve@mitre.org | https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/ | ||
cve@mitre.org | https://kc.mcafee.com/corporate/index?page=content&id=SB10340 | ||
cve@mitre.org | https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html | Third Party Advisory | |
cve@mitre.org | https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html | ||
cve@mitre.org | https://sites.google.com/site/itstheshappening | Third Party Advisory | |
cve@mitre.org | https://www.schneier.com/blog/archives/2005/02/sha1_broken.html | Third Party Advisory | |
cve@mitre.org | https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://ia.cr/2007/474 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://shattered.io/ | ||
af854a3a-2127-422b-91ae-364da2661108 | http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1 | ||
af854a3a-2127-422b-91ae-364da2661108 | http://www.securityfocus.com/bid/12577 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/ | ||
af854a3a-2127-422b-91ae-364da2661108 | https://kc.mcafee.com/corporate/index?page=content&id=SB10340 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html | ||
af854a3a-2127-422b-91ae-364da2661108 | https://sites.google.com/site/itstheshappening | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.schneier.com/blog/archives/2005/02/sha1_broken.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html | Third Party Advisory |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*", "matchCriteriaId": "AFB52550-C3FC-4CDD-AA6E-500BD3304241", "versionEndIncluding": "47.0.2526.111", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation." }, { "lang": "es", "value": "SHA-1 no es resistente a la colisi\u00f3n, lo que facilita a atacantes dependientes del contexto llevar a cabo ataques de espionaje, como es demostrado por ataques en el uso de SHA-1 en TLS 1.2. NOTA: esta CVE existe para dar un identificador com\u00fan para referenciar este problema de SHA-1; la existencia de un identificador no es, en si misma, una recomendaci\u00f3n tecnol\u00f3gica." } ], "evaluatorComment": "SHA-1 is likely present in a large number of products across the entire IT sector. The applicability statement for this CVE will be updated when specific products are identified, as time and resources permit.", "id": "CVE-2005-4900", "lastModified": "2025-04-12T10:46:40.837", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "exploitabilityScore": 2.2, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2016-10-14T16:59:00.187", "references": [ { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://ia.cr/2007/474" }, { "source": "cve@mitre.org", "url": "http://shattered.io/" }, { "source": "cve@mitre.org", "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/12577" }, { "source": "cve@mitre.org", "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "source": "cve@mitre.org", "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "source": "cve@mitre.org", "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://sites.google.com/site/itstheshappening" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://ia.cr/2007/474" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://shattered.io/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/12577" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://sites.google.com/site/itstheshappening" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-326" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
opensuse-su-2024:10786-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
git-2.33.0-1.3 on GA media
Notes
Title of the patch
git-2.33.0-1.3 on GA media
Description of the patch
These are all security issues fixed in the git-2.33.0-1.3 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-10786
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "git-2.33.0-1.3 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the git-2.33.0-1.3 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-10786", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_10786-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2005-4900 page", "url": "https://www.suse.com/security/cve/CVE-2005-4900/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-1000117 page", "url": "https://www.suse.com/security/cve/CVE-2017-1000117/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-14867 page", "url": "https://www.suse.com/security/cve/CVE-2017-14867/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-15298 page", "url": "https://www.suse.com/security/cve/CVE-2017-15298/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-8386 page", "url": "https://www.suse.com/security/cve/CVE-2017-8386/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-11233 page", "url": "https://www.suse.com/security/cve/CVE-2018-11233/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-11235 page", "url": "https://www.suse.com/security/cve/CVE-2018-11235/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-17456 page", "url": "https://www.suse.com/security/cve/CVE-2018-17456/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-19486 page", "url": "https://www.suse.com/security/cve/CVE-2018-19486/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1348 page", "url": "https://www.suse.com/security/cve/CVE-2019-1348/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1349 page", "url": "https://www.suse.com/security/cve/CVE-2019-1349/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1350 page", "url": "https://www.suse.com/security/cve/CVE-2019-1350/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1351 page", "url": "https://www.suse.com/security/cve/CVE-2019-1351/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1352 page", "url": "https://www.suse.com/security/cve/CVE-2019-1352/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1353 page", "url": "https://www.suse.com/security/cve/CVE-2019-1353/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1354 page", "url": "https://www.suse.com/security/cve/CVE-2019-1354/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1387 page", "url": "https://www.suse.com/security/cve/CVE-2019-1387/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-19604 page", "url": "https://www.suse.com/security/cve/CVE-2019-19604/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-11008 page", "url": "https://www.suse.com/security/cve/CVE-2020-11008/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-5260 page", "url": "https://www.suse.com/security/cve/CVE-2020-5260/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-21300 page", "url": "https://www.suse.com/security/cve/CVE-2021-21300/" } ], "title": "git-2.33.0-1.3 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:10786-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "git-2.33.0-1.3.aarch64", "product": { "name": "git-2.33.0-1.3.aarch64", "product_id": "git-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-arch-2.33.0-1.3.aarch64", "product": { "name": "git-arch-2.33.0-1.3.aarch64", "product_id": "git-arch-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-core-2.33.0-1.3.aarch64", "product": { "name": "git-core-2.33.0-1.3.aarch64", "product_id": "git-core-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-credential-gnome-keyring-2.33.0-1.3.aarch64", "product": { "name": "git-credential-gnome-keyring-2.33.0-1.3.aarch64", "product_id": "git-credential-gnome-keyring-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-credential-libsecret-2.33.0-1.3.aarch64", "product": { "name": "git-credential-libsecret-2.33.0-1.3.aarch64", "product_id": "git-credential-libsecret-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-cvs-2.33.0-1.3.aarch64", "product": { "name": "git-cvs-2.33.0-1.3.aarch64", "product_id": "git-cvs-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-daemon-2.33.0-1.3.aarch64", "product": { "name": "git-daemon-2.33.0-1.3.aarch64", "product_id": "git-daemon-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-doc-2.33.0-1.3.aarch64", "product": { "name": "git-doc-2.33.0-1.3.aarch64", "product_id": "git-doc-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-email-2.33.0-1.3.aarch64", "product": { "name": "git-email-2.33.0-1.3.aarch64", "product_id": "git-email-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-gui-2.33.0-1.3.aarch64", "product": { "name": "git-gui-2.33.0-1.3.aarch64", "product_id": "git-gui-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-p4-2.33.0-1.3.aarch64", "product": { "name": "git-p4-2.33.0-1.3.aarch64", "product_id": "git-p4-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-svn-2.33.0-1.3.aarch64", "product": { "name": "git-svn-2.33.0-1.3.aarch64", "product_id": "git-svn-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "git-web-2.33.0-1.3.aarch64", "product": { "name": "git-web-2.33.0-1.3.aarch64", "product_id": "git-web-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "gitk-2.33.0-1.3.aarch64", "product": { "name": "gitk-2.33.0-1.3.aarch64", "product_id": "gitk-2.33.0-1.3.aarch64" } }, { "category": "product_version", "name": "perl-Git-2.33.0-1.3.aarch64", "product": { "name": "perl-Git-2.33.0-1.3.aarch64", "product_id": "perl-Git-2.33.0-1.3.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "git-2.33.0-1.3.ppc64le", "product": { "name": "git-2.33.0-1.3.ppc64le", "product_id": "git-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-arch-2.33.0-1.3.ppc64le", "product": { "name": "git-arch-2.33.0-1.3.ppc64le", "product_id": "git-arch-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-core-2.33.0-1.3.ppc64le", "product": { "name": "git-core-2.33.0-1.3.ppc64le", "product_id": "git-core-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "product": { "name": "git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "product_id": "git-credential-gnome-keyring-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-credential-libsecret-2.33.0-1.3.ppc64le", "product": { "name": "git-credential-libsecret-2.33.0-1.3.ppc64le", "product_id": "git-credential-libsecret-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-cvs-2.33.0-1.3.ppc64le", "product": { "name": "git-cvs-2.33.0-1.3.ppc64le", "product_id": "git-cvs-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-daemon-2.33.0-1.3.ppc64le", "product": { "name": "git-daemon-2.33.0-1.3.ppc64le", "product_id": "git-daemon-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-doc-2.33.0-1.3.ppc64le", "product": { "name": "git-doc-2.33.0-1.3.ppc64le", "product_id": "git-doc-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-email-2.33.0-1.3.ppc64le", "product": { "name": "git-email-2.33.0-1.3.ppc64le", "product_id": "git-email-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-gui-2.33.0-1.3.ppc64le", "product": { "name": "git-gui-2.33.0-1.3.ppc64le", "product_id": "git-gui-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-p4-2.33.0-1.3.ppc64le", "product": { "name": "git-p4-2.33.0-1.3.ppc64le", "product_id": "git-p4-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-svn-2.33.0-1.3.ppc64le", "product": { "name": "git-svn-2.33.0-1.3.ppc64le", "product_id": "git-svn-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "git-web-2.33.0-1.3.ppc64le", "product": { "name": "git-web-2.33.0-1.3.ppc64le", "product_id": "git-web-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "gitk-2.33.0-1.3.ppc64le", "product": { "name": "gitk-2.33.0-1.3.ppc64le", "product_id": "gitk-2.33.0-1.3.ppc64le" } }, { "category": "product_version", "name": "perl-Git-2.33.0-1.3.ppc64le", "product": { "name": "perl-Git-2.33.0-1.3.ppc64le", "product_id": "perl-Git-2.33.0-1.3.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "git-2.33.0-1.3.s390x", "product": { "name": "git-2.33.0-1.3.s390x", "product_id": "git-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-arch-2.33.0-1.3.s390x", "product": { "name": "git-arch-2.33.0-1.3.s390x", "product_id": "git-arch-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-core-2.33.0-1.3.s390x", "product": { "name": "git-core-2.33.0-1.3.s390x", "product_id": "git-core-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-credential-gnome-keyring-2.33.0-1.3.s390x", "product": { "name": "git-credential-gnome-keyring-2.33.0-1.3.s390x", "product_id": "git-credential-gnome-keyring-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-credential-libsecret-2.33.0-1.3.s390x", "product": { "name": "git-credential-libsecret-2.33.0-1.3.s390x", "product_id": "git-credential-libsecret-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-cvs-2.33.0-1.3.s390x", "product": { "name": "git-cvs-2.33.0-1.3.s390x", "product_id": "git-cvs-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-daemon-2.33.0-1.3.s390x", "product": { "name": "git-daemon-2.33.0-1.3.s390x", "product_id": "git-daemon-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-doc-2.33.0-1.3.s390x", "product": { "name": "git-doc-2.33.0-1.3.s390x", "product_id": "git-doc-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-email-2.33.0-1.3.s390x", "product": { "name": "git-email-2.33.0-1.3.s390x", "product_id": "git-email-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-gui-2.33.0-1.3.s390x", "product": { "name": "git-gui-2.33.0-1.3.s390x", "product_id": "git-gui-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-p4-2.33.0-1.3.s390x", "product": { "name": "git-p4-2.33.0-1.3.s390x", "product_id": "git-p4-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-svn-2.33.0-1.3.s390x", "product": { "name": "git-svn-2.33.0-1.3.s390x", "product_id": "git-svn-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "git-web-2.33.0-1.3.s390x", "product": { "name": "git-web-2.33.0-1.3.s390x", "product_id": "git-web-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "gitk-2.33.0-1.3.s390x", "product": { "name": "gitk-2.33.0-1.3.s390x", "product_id": "gitk-2.33.0-1.3.s390x" } }, { "category": "product_version", "name": "perl-Git-2.33.0-1.3.s390x", "product": { "name": "perl-Git-2.33.0-1.3.s390x", "product_id": "perl-Git-2.33.0-1.3.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "git-2.33.0-1.3.x86_64", "product": { "name": "git-2.33.0-1.3.x86_64", "product_id": "git-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-arch-2.33.0-1.3.x86_64", "product": { "name": "git-arch-2.33.0-1.3.x86_64", "product_id": "git-arch-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-core-2.33.0-1.3.x86_64", "product": { "name": "git-core-2.33.0-1.3.x86_64", "product_id": "git-core-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-credential-gnome-keyring-2.33.0-1.3.x86_64", "product": { "name": "git-credential-gnome-keyring-2.33.0-1.3.x86_64", "product_id": "git-credential-gnome-keyring-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-credential-libsecret-2.33.0-1.3.x86_64", "product": { "name": "git-credential-libsecret-2.33.0-1.3.x86_64", "product_id": "git-credential-libsecret-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-cvs-2.33.0-1.3.x86_64", "product": { "name": "git-cvs-2.33.0-1.3.x86_64", "product_id": "git-cvs-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-daemon-2.33.0-1.3.x86_64", "product": { "name": "git-daemon-2.33.0-1.3.x86_64", "product_id": "git-daemon-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-doc-2.33.0-1.3.x86_64", "product": { "name": "git-doc-2.33.0-1.3.x86_64", "product_id": "git-doc-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-email-2.33.0-1.3.x86_64", "product": { "name": "git-email-2.33.0-1.3.x86_64", "product_id": "git-email-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-gui-2.33.0-1.3.x86_64", "product": { "name": "git-gui-2.33.0-1.3.x86_64", "product_id": "git-gui-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-p4-2.33.0-1.3.x86_64", "product": { "name": "git-p4-2.33.0-1.3.x86_64", "product_id": "git-p4-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-svn-2.33.0-1.3.x86_64", "product": { "name": "git-svn-2.33.0-1.3.x86_64", "product_id": "git-svn-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "git-web-2.33.0-1.3.x86_64", "product": { "name": "git-web-2.33.0-1.3.x86_64", "product_id": "git-web-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "gitk-2.33.0-1.3.x86_64", "product": { "name": "gitk-2.33.0-1.3.x86_64", "product_id": "gitk-2.33.0-1.3.x86_64" } }, { "category": "product_version", "name": "perl-Git-2.33.0-1.3.x86_64", "product": { "name": "perl-Git-2.33.0-1.3.x86_64", "product_id": "perl-Git-2.33.0-1.3.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "git-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64" }, "product_reference": "git-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le" }, "product_reference": "git-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-2.33.0-1.3.s390x" }, "product_reference": "git-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64" }, "product_reference": "git-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-arch-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64" }, "product_reference": "git-arch-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-arch-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le" }, "product_reference": "git-arch-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-arch-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x" }, "product_reference": "git-arch-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-arch-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64" }, "product_reference": "git-arch-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64" }, "product_reference": "git-core-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le" }, "product_reference": "git-core-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x" }, "product_reference": "git-core-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64" }, "product_reference": "git-core-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-gnome-keyring-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64" }, "product_reference": "git-credential-gnome-keyring-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-gnome-keyring-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le" }, "product_reference": "git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-gnome-keyring-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x" }, "product_reference": "git-credential-gnome-keyring-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-gnome-keyring-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64" }, "product_reference": "git-credential-gnome-keyring-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-libsecret-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64" }, "product_reference": "git-credential-libsecret-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-libsecret-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le" }, "product_reference": "git-credential-libsecret-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-libsecret-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x" }, "product_reference": "git-credential-libsecret-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-credential-libsecret-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64" }, "product_reference": "git-credential-libsecret-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-cvs-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64" }, "product_reference": "git-cvs-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-cvs-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le" }, "product_reference": "git-cvs-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-cvs-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x" }, "product_reference": "git-cvs-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-cvs-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64" }, "product_reference": "git-cvs-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-daemon-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64" }, "product_reference": "git-daemon-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-daemon-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le" }, "product_reference": "git-daemon-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-daemon-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x" }, "product_reference": "git-daemon-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-daemon-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64" }, "product_reference": "git-daemon-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-doc-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64" }, "product_reference": "git-doc-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-doc-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le" }, "product_reference": "git-doc-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-doc-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x" }, "product_reference": "git-doc-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-doc-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64" }, "product_reference": "git-doc-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-email-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64" }, "product_reference": "git-email-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-email-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le" }, "product_reference": "git-email-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-email-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x" }, "product_reference": "git-email-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-email-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64" }, "product_reference": "git-email-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-gui-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64" }, "product_reference": "git-gui-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-gui-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le" }, "product_reference": "git-gui-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-gui-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x" }, "product_reference": "git-gui-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-gui-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64" }, "product_reference": "git-gui-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-p4-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64" }, "product_reference": "git-p4-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-p4-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le" }, "product_reference": "git-p4-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-p4-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x" }, "product_reference": "git-p4-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-p4-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64" }, "product_reference": "git-p4-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-svn-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64" }, "product_reference": "git-svn-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-svn-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le" }, "product_reference": "git-svn-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-svn-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x" }, "product_reference": "git-svn-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-svn-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64" }, "product_reference": "git-svn-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-web-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64" }, "product_reference": "git-web-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-web-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le" }, "product_reference": "git-web-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-web-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x" }, "product_reference": "git-web-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "git-web-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64" }, "product_reference": "git-web-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "gitk-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64" }, "product_reference": "gitk-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "gitk-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le" }, "product_reference": "gitk-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "gitk-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x" }, "product_reference": "gitk-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "gitk-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64" }, "product_reference": "gitk-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.33.0-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64" }, "product_reference": "perl-Git-2.33.0-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.33.0-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le" }, "product_reference": "perl-Git-2.33.0-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.33.0-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x" }, "product_reference": "perl-Git-2.33.0-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.33.0-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" }, "product_reference": "perl-Git-2.33.0-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2005-4900", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2005-4900" } ], "notes": [ { "category": "general", "text": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2005-4900", "url": "https://www.suse.com/security/cve/CVE-2005-4900" }, { "category": "external", "summary": "SUSE Bug 1026646 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026646" }, { "category": "external", "summary": "SUSE Bug 1026936 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026936" }, { "category": "external", "summary": "SUSE Bug 1042640 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1042640" }, { "category": "external", "summary": "SUSE Bug 1150998 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1150998" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2005-4900" }, { "cve": "CVE-2017-1000117", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-1000117" } ], "notes": [ { "category": "general", "text": "A malicious third-party can give a crafted \"ssh://...\" URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim\u0027s machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running \"git clone --recurse-submodules\" to trigger the vulnerability.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-1000117", "url": "https://www.suse.com/security/cve/CVE-2017-1000117" }, { "category": "external", "summary": "SUSE Bug 1052481 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1052481" }, { "category": "external", "summary": "SUSE Bug 1052696 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1052696" }, { "category": "external", "summary": "SUSE Bug 1052932 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1052932" }, { "category": "external", "summary": "SUSE Bug 1053364 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1053364" }, { "category": "external", "summary": "SUSE Bug 1053600 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1053600" }, { "category": "external", "summary": "SUSE Bug 1053919 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1053919" }, { "category": "external", "summary": "SUSE Bug 1054653 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1054653" }, { "category": "external", "summary": "SUSE Bug 1058214 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1058214" }, { "category": "external", "summary": "SUSE Bug 1066430 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1066430" }, { "category": "external", "summary": "SUSE Bug 1071709 for CVE-2017-1000117", "url": "https://bugzilla.suse.com/1071709" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2017-1000117" }, { "cve": "CVE-2017-14867", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-14867" } ], "notes": [ { "category": "general", "text": "Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-14867", "url": "https://www.suse.com/security/cve/CVE-2017-14867" }, { "category": "external", "summary": "SUSE Bug 1060377 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1060377" }, { "category": "external", "summary": "SUSE Bug 1060378 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1060378" }, { "category": "external", "summary": "SUSE Bug 1061041 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1061041" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2017-14867" }, { "cve": "CVE-2017-15298", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-15298" } ], "notes": [ { "category": "general", "text": "Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-15298", "url": "https://www.suse.com/security/cve/CVE-2017-15298" }, { "category": "external", "summary": "SUSE Bug 1063412 for CVE-2017-15298", "url": "https://bugzilla.suse.com/1063412" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "low" } ], "title": "CVE-2017-15298" }, { "cve": "CVE-2017-8386", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-8386" } ], "notes": [ { "category": "general", "text": "git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-8386", "url": "https://www.suse.com/security/cve/CVE-2017-8386" }, { "category": "external", "summary": "SUSE Bug 1038395 for CVE-2017-8386", "url": "https://bugzilla.suse.com/1038395" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-8386" }, { "cve": "CVE-2018-11233", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-11233" } ], "notes": [ { "category": "general", "text": "In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-11233", "url": "https://www.suse.com/security/cve/CVE-2018-11233" }, { "category": "external", "summary": "SUSE Bug 1095218 for CVE-2018-11233", "url": "https://bugzilla.suse.com/1095218" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-11233" }, { "cve": "CVE-2018-11235", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-11235" } ], "notes": [ { "category": "general", "text": "In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs \"git clone --recurse-submodules\" because submodule \"names\" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with \"../\" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-11235", "url": "https://www.suse.com/security/cve/CVE-2018-11235" }, { "category": "external", "summary": "SUSE Bug 1095219 for CVE-2018-11235", "url": "https://bugzilla.suse.com/1095219" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-11235" }, { "cve": "CVE-2018-17456", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-17456" } ], "notes": [ { "category": "general", "text": "Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive \"git clone\" of a superproject if a .gitmodules file has a URL field beginning with a \u0027-\u0027 character.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-17456", "url": "https://www.suse.com/security/cve/CVE-2018-17456" }, { "category": "external", "summary": "SUSE Bug 1110949 for CVE-2018-17456", "url": "https://bugzilla.suse.com/1110949" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-17456" }, { "cve": "CVE-2018-19486", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-19486" } ], "notes": [ { "category": "general", "text": "Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if \u0027.\u0027 were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-19486", "url": "https://www.suse.com/security/cve/CVE-2018-19486" }, { "category": "external", "summary": "SUSE Bug 1117257 for CVE-2018-19486", "url": "https://bugzilla.suse.com/1117257" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-19486" }, { "cve": "CVE-2019-1348", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1348" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1348", "url": "https://www.suse.com/security/cve/CVE-2019-1348" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1348", "url": "https://bugzilla.suse.com/1158785" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-1348" }, { "cve": "CVE-2019-1349", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1349" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1349", "url": "https://www.suse.com/security/cve/CVE-2019-1349" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1349", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158787 for CVE-2019-1349", "url": "https://bugzilla.suse.com/1158787" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1349" }, { "cve": "CVE-2019-1350", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1350" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1350", "url": "https://www.suse.com/security/cve/CVE-2019-1350" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1350", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158788 for CVE-2019-1350", "url": "https://bugzilla.suse.com/1158788" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1350" }, { "cve": "CVE-2019-1351", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1351" } ], "notes": [ { "category": "general", "text": "A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka \u0027Git for Visual Studio Tampering Vulnerability\u0027.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1351", "url": "https://www.suse.com/security/cve/CVE-2019-1351" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1351", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158789 for CVE-2019-1351", "url": "https://bugzilla.suse.com/1158789" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1351" }, { "cve": "CVE-2019-1352", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1352" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1352", "url": "https://www.suse.com/security/cve/CVE-2019-1352" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158787 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158787" }, { "category": "external", "summary": "SUSE Bug 1158790 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158790" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1352" }, { "cve": "CVE-2019-1353", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1353" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as \"WSL\") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1353", "url": "https://www.suse.com/security/cve/CVE-2019-1353" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1353", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158791 for CVE-2019-1353", "url": "https://bugzilla.suse.com/1158791" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2019-1353" }, { "cve": "CVE-2019-1354", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1354" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1354", "url": "https://www.suse.com/security/cve/CVE-2019-1354" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1354", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158792 for CVE-2019-1354", "url": "https://bugzilla.suse.com/1158792" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-1354" }, { "cve": "CVE-2019-1387", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1387" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1387", "url": "https://www.suse.com/security/cve/CVE-2019-1387" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1387", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158793 for CVE-2019-1387", "url": "https://bugzilla.suse.com/1158793" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1387" }, { "cve": "CVE-2019-19604", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-19604" } ], "notes": [ { "category": "general", "text": "Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a \"git submodule update\" operation can run commands found in the .gitmodules file of a malicious repository.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-19604", "url": "https://www.suse.com/security/cve/CVE-2019-19604" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-19604", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158795 for CVE-2019-19604", "url": "https://bugzilla.suse.com/1158795" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-19604" }, { "cve": "CVE-2020-11008", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-11008" } ], "notes": [ { "category": "general", "text": "Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external \"credential helper\" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a \"blank\" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker\u0027s server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git\u0027s \"store\" helper - Git\u0027s \"cache\" helper - the \"osxkeychain\" helper that ships in Git\u0027s \"contrib\" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-11008", "url": "https://www.suse.com/security/cve/CVE-2020-11008" }, { "category": "external", "summary": "SUSE Bug 1169936 for CVE-2020-11008", "url": "https://bugzilla.suse.com/1169936" }, { "category": "external", "summary": "SUSE Bug 1170741 for CVE-2020-11008", "url": "https://bugzilla.suse.com/1170741" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2020-11008" }, { "cve": "CVE-2020-5260", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-5260" } ], "notes": [ { "category": "general", "text": "Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external \"credential helper\" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can inject unintended values into the credential helper protocol stream, causing the credential helper to retrieve the password for one server (e.g., good.example.com) for an HTTP request being made to another server (e.g., evil.example.com), resulting in credentials for the former being sent to the latter. There are no restrictions on the relationship between the two, meaning that an attacker can craft a URL that will present stored credentials for any host to a host of their choosing. The vulnerability can be triggered by feeding a malicious URL to git clone. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The problem has been patched in the versions published on April 14th, 2020, going back to v2.17.x. Anyone wishing to backport the change further can do so by applying commit 9a6bbee (the full release includes extra checks for git fsck, but that commit is sufficient to protect clients against the vulnerability). The patched versions are: 2.17.4, 2.18.3, 2.19.4, 2.20.3, 2.21.2, 2.22.3, 2.23.2, 2.24.2, 2.25.3, 2.26.1.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-5260", "url": "https://www.suse.com/security/cve/CVE-2020-5260" }, { "category": "external", "summary": "SUSE Bug 1168930 for CVE-2020-5260", "url": "https://bugzilla.suse.com/1168930" }, { "category": "external", "summary": "SUSE Bug 1169936 for CVE-2020-5260", "url": "https://bugzilla.suse.com/1169936" }, { "category": "external", "summary": "SUSE Bug 1170741 for CVE-2020-5260", "url": "https://bugzilla.suse.com/1170741" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2020-5260" }, { "cve": "CVE-2021-21300", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-21300" } ], "notes": [ { "category": "general", "text": "Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March 9th, 2021. As a workaound, if symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won\u0027t work. Likewise, if no clean/smudge filters such as Git LFS are configured globally (i.e. _before_ cloning), the attack is foiled. As always, it is best to avoid cloning repositories from untrusted sources. The earliest impacted version is 2.14.2. The fix versions are: 2.30.1, 2.29.3, 2.28.1, 2.27.1, 2.26.3, 2.25.5, 2.24.4, 2.23.4, 2.22.5, 2.21.4, 2.20.5, 2.19.6, 2.18.5, 2.17.62.17.6.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-21300", "url": "https://www.suse.com/security/cve/CVE-2021-21300" }, { "category": "external", "summary": "SUSE Bug 1183026 for CVE-2021-21300", "url": "https://bugzilla.suse.com/1183026" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-arch-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-core-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-core-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-core-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-cvs-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-daemon-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-doc-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-email-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-email-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-email-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-gui-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-p4-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-svn-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:git-web-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:git-web-2.33.0-1.3.s390x", "openSUSE Tumbleweed:git-web-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:gitk-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:gitk-2.33.0-1.3.s390x", "openSUSE Tumbleweed:gitk-2.33.0-1.3.x86_64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.aarch64", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.ppc64le", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.s390x", "openSUSE Tumbleweed:perl-Git-2.33.0-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2021-21300" } ] }
opensuse-su-2024:10943-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
libgit2-1_1-1.1.1-1.2 on GA media
Notes
Title of the patch
libgit2-1_1-1.1.1-1.2 on GA media
Description of the patch
These are all security issues fixed in the libgit2-1_1-1.1.1-1.2 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-10943
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "libgit2-1_1-1.1.1-1.2 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the libgit2-1_1-1.1.1-1.2 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-10943", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_10943-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2005-4900 page", "url": "https://www.suse.com/security/cve/CVE-2005-4900/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-10128 page", "url": "https://www.suse.com/security/cve/CVE-2016-10128/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-10130 page", "url": "https://www.suse.com/security/cve/CVE-2016-10130/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-10887 page", "url": "https://www.suse.com/security/cve/CVE-2018-10887/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-11235 page", "url": "https://www.suse.com/security/cve/CVE-2018-11235/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-17456 page", "url": "https://www.suse.com/security/cve/CVE-2018-17456/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-8098 page", "url": "https://www.suse.com/security/cve/CVE-2018-8098/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1348 page", "url": "https://www.suse.com/security/cve/CVE-2019-1348/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1349 page", "url": "https://www.suse.com/security/cve/CVE-2019-1349/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1350 page", "url": "https://www.suse.com/security/cve/CVE-2019-1350/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1351 page", "url": "https://www.suse.com/security/cve/CVE-2019-1351/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1352 page", "url": "https://www.suse.com/security/cve/CVE-2019-1352/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1353 page", "url": "https://www.suse.com/security/cve/CVE-2019-1353/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1354 page", "url": "https://www.suse.com/security/cve/CVE-2019-1354/" }, { "category": "self", "summary": "SUSE CVE CVE-2019-1387 page", "url": "https://www.suse.com/security/cve/CVE-2019-1387/" } ], "title": "libgit2-1_1-1.1.1-1.2 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:10943-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "libgit2-1_1-1.1.1-1.2.aarch64", "product": { "name": "libgit2-1_1-1.1.1-1.2.aarch64", "product_id": "libgit2-1_1-1.1.1-1.2.aarch64" } }, { "category": "product_version", "name": "libgit2-1_1-32bit-1.1.1-1.2.aarch64", "product": { "name": "libgit2-1_1-32bit-1.1.1-1.2.aarch64", "product_id": "libgit2-1_1-32bit-1.1.1-1.2.aarch64" } }, { "category": "product_version", "name": "libgit2-devel-1.1.1-1.2.aarch64", "product": { "name": "libgit2-devel-1.1.1-1.2.aarch64", "product_id": "libgit2-devel-1.1.1-1.2.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "libgit2-1_1-1.1.1-1.2.ppc64le", "product": { "name": "libgit2-1_1-1.1.1-1.2.ppc64le", "product_id": "libgit2-1_1-1.1.1-1.2.ppc64le" } }, { "category": "product_version", "name": "libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "product": { "name": "libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "product_id": "libgit2-1_1-32bit-1.1.1-1.2.ppc64le" } }, { "category": "product_version", "name": "libgit2-devel-1.1.1-1.2.ppc64le", "product": { "name": "libgit2-devel-1.1.1-1.2.ppc64le", "product_id": "libgit2-devel-1.1.1-1.2.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "libgit2-1_1-1.1.1-1.2.s390x", "product": { "name": "libgit2-1_1-1.1.1-1.2.s390x", "product_id": "libgit2-1_1-1.1.1-1.2.s390x" } }, { "category": "product_version", "name": "libgit2-1_1-32bit-1.1.1-1.2.s390x", "product": { "name": "libgit2-1_1-32bit-1.1.1-1.2.s390x", "product_id": "libgit2-1_1-32bit-1.1.1-1.2.s390x" } }, { "category": "product_version", "name": "libgit2-devel-1.1.1-1.2.s390x", "product": { "name": "libgit2-devel-1.1.1-1.2.s390x", "product_id": "libgit2-devel-1.1.1-1.2.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "libgit2-1_1-1.1.1-1.2.x86_64", "product": { "name": "libgit2-1_1-1.1.1-1.2.x86_64", "product_id": "libgit2-1_1-1.1.1-1.2.x86_64" } }, { "category": "product_version", "name": "libgit2-1_1-32bit-1.1.1-1.2.x86_64", "product": { "name": "libgit2-1_1-32bit-1.1.1-1.2.x86_64", "product_id": "libgit2-1_1-32bit-1.1.1-1.2.x86_64" } }, { "category": "product_version", "name": "libgit2-devel-1.1.1-1.2.x86_64", "product": { "name": "libgit2-devel-1.1.1-1.2.x86_64", "product_id": "libgit2-devel-1.1.1-1.2.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-1.1.1-1.2.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64" }, "product_reference": "libgit2-1_1-1.1.1-1.2.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-1.1.1-1.2.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le" }, "product_reference": "libgit2-1_1-1.1.1-1.2.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-1.1.1-1.2.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x" }, "product_reference": "libgit2-1_1-1.1.1-1.2.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-1.1.1-1.2.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64" }, "product_reference": "libgit2-1_1-1.1.1-1.2.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-32bit-1.1.1-1.2.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64" }, "product_reference": "libgit2-1_1-32bit-1.1.1-1.2.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-32bit-1.1.1-1.2.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le" }, "product_reference": "libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-32bit-1.1.1-1.2.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x" }, "product_reference": "libgit2-1_1-32bit-1.1.1-1.2.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-1_1-32bit-1.1.1-1.2.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64" }, "product_reference": "libgit2-1_1-32bit-1.1.1-1.2.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-devel-1.1.1-1.2.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64" }, "product_reference": "libgit2-devel-1.1.1-1.2.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-devel-1.1.1-1.2.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le" }, "product_reference": "libgit2-devel-1.1.1-1.2.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-devel-1.1.1-1.2.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x" }, "product_reference": "libgit2-devel-1.1.1-1.2.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libgit2-devel-1.1.1-1.2.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" }, "product_reference": "libgit2-devel-1.1.1-1.2.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2005-4900", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2005-4900" } ], "notes": [ { "category": "general", "text": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2005-4900", "url": "https://www.suse.com/security/cve/CVE-2005-4900" }, { "category": "external", "summary": "SUSE Bug 1026646 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026646" }, { "category": "external", "summary": "SUSE Bug 1026936 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026936" }, { "category": "external", "summary": "SUSE Bug 1042640 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1042640" }, { "category": "external", "summary": "SUSE Bug 1150998 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1150998" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2005-4900" }, { "cve": "CVE-2016-10128", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-10128" } ], "notes": [ { "category": "general", "text": "Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-10128", "url": "https://www.suse.com/security/cve/CVE-2016-10128" }, { "category": "external", "summary": "SUSE Bug 1019036 for CVE-2016-10128", "url": "https://bugzilla.suse.com/1019036" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-10128" }, { "cve": "CVE-2016-10130", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-10130" } ], "notes": [ { "category": "general", "text": "The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-10130", "url": "https://www.suse.com/security/cve/CVE-2016-10130" }, { "category": "external", "summary": "SUSE Bug 1019037 for CVE-2016-10130", "url": "https://bugzilla.suse.com/1019037" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2016-10130" }, { "cve": "CVE-2018-10887", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-10887" } ], "notes": [ { "category": "general", "text": "A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-10887", "url": "https://www.suse.com/security/cve/CVE-2018-10887" }, { "category": "external", "summary": "SUSE Bug 1100613 for CVE-2018-10887", "url": "https://bugzilla.suse.com/1100613" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-10887" }, { "cve": "CVE-2018-11235", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-11235" } ], "notes": [ { "category": "general", "text": "In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs \"git clone --recurse-submodules\" because submodule \"names\" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with \"../\" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-11235", "url": "https://www.suse.com/security/cve/CVE-2018-11235" }, { "category": "external", "summary": "SUSE Bug 1095219 for CVE-2018-11235", "url": "https://bugzilla.suse.com/1095219" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-11235" }, { "cve": "CVE-2018-17456", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-17456" } ], "notes": [ { "category": "general", "text": "Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive \"git clone\" of a superproject if a .gitmodules file has a URL field beginning with a \u0027-\u0027 character.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-17456", "url": "https://www.suse.com/security/cve/CVE-2018-17456" }, { "category": "external", "summary": "SUSE Bug 1110949 for CVE-2018-17456", "url": "https://bugzilla.suse.com/1110949" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2018-17456" }, { "cve": "CVE-2018-8098", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-8098" } ], "notes": [ { "category": "general", "text": "Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-8098", "url": "https://www.suse.com/security/cve/CVE-2018-8098" }, { "category": "external", "summary": "SUSE Bug 1085256 for CVE-2018-8098", "url": "https://bugzilla.suse.com/1085256" }, { "category": "external", "summary": "SUSE Bug 1085257 for CVE-2018-8098", "url": "https://bugzilla.suse.com/1085257" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-8098" }, { "cve": "CVE-2019-1348", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1348" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1348", "url": "https://www.suse.com/security/cve/CVE-2019-1348" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1348", "url": "https://bugzilla.suse.com/1158785" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-1348" }, { "cve": "CVE-2019-1349", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1349" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1349", "url": "https://www.suse.com/security/cve/CVE-2019-1349" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1349", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158787 for CVE-2019-1349", "url": "https://bugzilla.suse.com/1158787" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1349" }, { "cve": "CVE-2019-1350", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1350" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1350", "url": "https://www.suse.com/security/cve/CVE-2019-1350" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1350", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158788 for CVE-2019-1350", "url": "https://bugzilla.suse.com/1158788" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1350" }, { "cve": "CVE-2019-1351", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1351" } ], "notes": [ { "category": "general", "text": "A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka \u0027Git for Visual Studio Tampering Vulnerability\u0027.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1351", "url": "https://www.suse.com/security/cve/CVE-2019-1351" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1351", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158789 for CVE-2019-1351", "url": "https://bugzilla.suse.com/1158789" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1351" }, { "cve": "CVE-2019-1352", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1352" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1352", "url": "https://www.suse.com/security/cve/CVE-2019-1352" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158787 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158787" }, { "category": "external", "summary": "SUSE Bug 1158790 for CVE-2019-1352", "url": "https://bugzilla.suse.com/1158790" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1352" }, { "cve": "CVE-2019-1353", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1353" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as \"WSL\") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1353", "url": "https://www.suse.com/security/cve/CVE-2019-1353" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1353", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158791 for CVE-2019-1353", "url": "https://bugzilla.suse.com/1158791" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "critical" } ], "title": "CVE-2019-1353" }, { "cve": "CVE-2019-1354", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1354" } ], "notes": [ { "category": "general", "text": "A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka \u0027Git for Visual Studio Remote Code Execution Vulnerability\u0027. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1354", "url": "https://www.suse.com/security/cve/CVE-2019-1354" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1354", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158792 for CVE-2019-1354", "url": "https://bugzilla.suse.com/1158792" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2019-1354" }, { "cve": "CVE-2019-1387", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2019-1387" } ], "notes": [ { "category": "general", "text": "An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2019-1387", "url": "https://www.suse.com/security/cve/CVE-2019-1387" }, { "category": "external", "summary": "SUSE Bug 1158785 for CVE-2019-1387", "url": "https://bugzilla.suse.com/1158785" }, { "category": "external", "summary": "SUSE Bug 1158793 for CVE-2019-1387", "url": "https://bugzilla.suse.com/1158793" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-1_1-32bit-1.1.1-1.2.x86_64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.aarch64", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.ppc64le", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.s390x", "openSUSE Tumbleweed:libgit2-devel-1.1.1-1.2.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2019-1387" } ] }
opensuse-su-2024:11377-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
libsha1detectcoll-devel-1.0.3-4.12 on GA media
Notes
Title of the patch
libsha1detectcoll-devel-1.0.3-4.12 on GA media
Description of the patch
These are all security issues fixed in the libsha1detectcoll-devel-1.0.3-4.12 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-11377
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "libsha1detectcoll-devel-1.0.3-4.12 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the libsha1detectcoll-devel-1.0.3-4.12 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-11377", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_11377-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2005-4900 page", "url": "https://www.suse.com/security/cve/CVE-2005-4900/" } ], "title": "libsha1detectcoll-devel-1.0.3-4.12 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:11377-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "libsha1detectcoll-devel-1.0.3-4.12.aarch64", "product": { "name": "libsha1detectcoll-devel-1.0.3-4.12.aarch64", "product_id": "libsha1detectcoll-devel-1.0.3-4.12.aarch64" } }, { "category": "product_version", "name": "libsha1detectcoll1-1.0.3-4.12.aarch64", "product": { "name": "libsha1detectcoll1-1.0.3-4.12.aarch64", "product_id": "libsha1detectcoll1-1.0.3-4.12.aarch64" } }, { "category": "product_version", "name": "sha1collisiondetection-1.0.3-4.12.aarch64", "product": { "name": "sha1collisiondetection-1.0.3-4.12.aarch64", "product_id": "sha1collisiondetection-1.0.3-4.12.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "product": { "name": "libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "product_id": "libsha1detectcoll-devel-1.0.3-4.12.ppc64le" } }, { "category": "product_version", "name": "libsha1detectcoll1-1.0.3-4.12.ppc64le", "product": { "name": "libsha1detectcoll1-1.0.3-4.12.ppc64le", "product_id": "libsha1detectcoll1-1.0.3-4.12.ppc64le" } }, { "category": "product_version", "name": "sha1collisiondetection-1.0.3-4.12.ppc64le", "product": { "name": "sha1collisiondetection-1.0.3-4.12.ppc64le", "product_id": "sha1collisiondetection-1.0.3-4.12.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "libsha1detectcoll-devel-1.0.3-4.12.s390x", "product": { "name": "libsha1detectcoll-devel-1.0.3-4.12.s390x", "product_id": "libsha1detectcoll-devel-1.0.3-4.12.s390x" } }, { "category": "product_version", "name": "libsha1detectcoll1-1.0.3-4.12.s390x", "product": { "name": "libsha1detectcoll1-1.0.3-4.12.s390x", "product_id": "libsha1detectcoll1-1.0.3-4.12.s390x" } }, { "category": "product_version", "name": "sha1collisiondetection-1.0.3-4.12.s390x", "product": { "name": "sha1collisiondetection-1.0.3-4.12.s390x", "product_id": "sha1collisiondetection-1.0.3-4.12.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "libsha1detectcoll-devel-1.0.3-4.12.x86_64", "product": { "name": "libsha1detectcoll-devel-1.0.3-4.12.x86_64", "product_id": "libsha1detectcoll-devel-1.0.3-4.12.x86_64" } }, { "category": "product_version", "name": "libsha1detectcoll1-1.0.3-4.12.x86_64", "product": { "name": "libsha1detectcoll1-1.0.3-4.12.x86_64", "product_id": "libsha1detectcoll1-1.0.3-4.12.x86_64" } }, { "category": "product_version", "name": "sha1collisiondetection-1.0.3-4.12.x86_64", "product": { "name": "sha1collisiondetection-1.0.3-4.12.x86_64", "product_id": "sha1collisiondetection-1.0.3-4.12.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll-devel-1.0.3-4.12.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.aarch64" }, "product_reference": "libsha1detectcoll-devel-1.0.3-4.12.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll-devel-1.0.3-4.12.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.ppc64le" }, "product_reference": "libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll-devel-1.0.3-4.12.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.s390x" }, "product_reference": "libsha1detectcoll-devel-1.0.3-4.12.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll-devel-1.0.3-4.12.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.x86_64" }, "product_reference": "libsha1detectcoll-devel-1.0.3-4.12.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll1-1.0.3-4.12.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.aarch64" }, "product_reference": "libsha1detectcoll1-1.0.3-4.12.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll1-1.0.3-4.12.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.ppc64le" }, "product_reference": "libsha1detectcoll1-1.0.3-4.12.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll1-1.0.3-4.12.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.s390x" }, "product_reference": "libsha1detectcoll1-1.0.3-4.12.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "libsha1detectcoll1-1.0.3-4.12.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.x86_64" }, "product_reference": "libsha1detectcoll1-1.0.3-4.12.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "sha1collisiondetection-1.0.3-4.12.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.aarch64" }, "product_reference": "sha1collisiondetection-1.0.3-4.12.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "sha1collisiondetection-1.0.3-4.12.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.ppc64le" }, "product_reference": "sha1collisiondetection-1.0.3-4.12.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "sha1collisiondetection-1.0.3-4.12.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.s390x" }, "product_reference": "sha1collisiondetection-1.0.3-4.12.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "sha1collisiondetection-1.0.3-4.12.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.x86_64" }, "product_reference": "sha1collisiondetection-1.0.3-4.12.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2005-4900", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2005-4900" } ], "notes": [ { "category": "general", "text": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.s390x", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2005-4900", "url": "https://www.suse.com/security/cve/CVE-2005-4900" }, { "category": "external", "summary": "SUSE Bug 1026646 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026646" }, { "category": "external", "summary": "SUSE Bug 1026936 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026936" }, { "category": "external", "summary": "SUSE Bug 1042640 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1042640" }, { "category": "external", "summary": "SUSE Bug 1150998 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1150998" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.s390x", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll-devel-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.s390x", "openSUSE Tumbleweed:libsha1detectcoll1-1.0.3-4.12.x86_64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.aarch64", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.ppc64le", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.s390x", "openSUSE Tumbleweed:sha1collisiondetection-1.0.3-4.12.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2005-4900" } ] }
suse-su-2025:20049-1
Vulnerability from csaf_suse
Published
2025-02-03 08:55
Modified
2025-02-03 08:55
Summary
Security update for git
Notes
Title of the patch
Security update for git
Description of the patch
This update for git fixes the following issues:
git was updated to 2.45.1:
* CVE-2024-32002: recursive clones on case-insensitive
filesystems that support symbolic links are susceptible to case
confusion (bsc#1224168)
* CVE-2024-32004: arbitrary code execution during local clones
(bsc#1224170)
* CVE-2024-32020: file overwriting vulnerability during local
clones (bsc#1224171)
* CVE-2024-32021: git may create hardlinks to arbitrary user-
readable files (bsc#1224172)
* CVE-2024-32465: arbitrary code execution during clone operations
(bsc#1224173)
Update to 2.45.0:
* Improved efficiency managing repositories with many references
("git init --ref-format=reftable")
* "git checkout -p" and friends learned that that "@" is a
synonym for "HEAD"
* cli improvements handling refs
* Expanded a number of commands and options, UI improvements
* status.showUntrackedFiles now accepts "true"
* git-cherry-pick(1) now automatically drops redundant commits
with new --empty option
* The userdiff patterns for C# has been updated.
Update to 2.44.0:
* "git checkout -B <branch>" now longer allows switching to a
branch that is in use on another worktree. The users need to
use "--ignore-other-worktrees" option.
* Faster server-side rebases with git replay
* Faster pack generation with multi-pack reuse
* rebase auto-squashing now works in non-interactive mode
* pathspec now understands attr, e.g. ':(attr:~binary) for
selecting non-binaries, or builtin_objectmode for selecting
items by file mode or other properties
* Many other cli UI and internal improvements and extensions
- Do not replace apparmor configuration, fixes bsc#1216545
Update to 2.43.2:
* https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.2.txt
* Update to a new feature recently added, "git show-ref --exists".
* Rename detection logic ignored the final line of a file if it
is an incomplete line.
* "git diff --no-rename A B" did not disable rename detection but
did not trigger an error from the command line parser.
* "git diff --no-index file1 file2" segfaulted while invoking the
external diff driver, which has been corrected.
* A failed "git tag -s" did not necessarily result in an error
depending on the crypto backend, which has been corrected.
* "git stash" sometimes was silent even when it failed due to
unwritable index file, which has been corrected.
* Recent conversion to allow more than 0/1 in GIT_FLUSH broke the
mechanism by flipping what yes/no means by mistake, which has
been corrected.
Update to 2.43.1:
* https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.1.txt
- gitweb AppArmor profile: allow reading etc/gitweb-common.conf
(bsc#1218664)
- git moved to /usr/libexec/git/git, update AppArmor profile
accordingly (bsc#1218588)
Update to 2.43.0:
* The "--rfc" option of "git format-patch" used to be a valid way to
override an earlier "--subject-prefix=<something>" on the command
line and replace it with "[RFC PATCH]", but from this release, it
merely prefixes the string "RFC " in front of the given subject
prefix. If you are negatively affected by this change, please use
"--subject-prefix=PATCH --rfc" as a replacement.
* In Git 2.42, "git rev-list --stdin" learned to take non-revisions
(like "--not") from the standard input, but the way such a "--not" was
handled was quite confusing, which has been rethought. The updated
rule is that "--not" given from the command line only affects revs
given from the command line that comes but not revs read from the
standard input, and "--not" read from the standard input affects
revs given from the standard input and not revs given from the
command line.
* A message written in olden time prevented a branch from getting
checked out, saying it is already checked out elsewhere. But these
days, we treat a branch that is being bisected or rebased just like
a branch that is checked out and protect it from getting modified
with the same codepath. The message has been rephrased to say that
the branch is "in use" to avoid confusion.
* Hourly and other schedules of "git maintenance" jobs are randomly
distributed now.
* "git cmd -h" learned to signal which options can be negated by
listing such options like "--[no-]opt".
* The way authentication related data other than passwords (e.g.,
oauth token and password expiration data) are stored in libsecret
keyrings has been rethought.
* Update the libsecret and wincred credential helpers to correctly
match which credential to erase; they erased the wrong entry in
some cases.
* Git GUI updates.
* "git format-patch" learned a new "--description-file" option that
lets cover letter description to be fed; this can be used on
detached HEAD where there is no branch description available, and
also can override the branch description if there is one.
* Use of the "--max-pack-size" option to allow multiple packfiles to
be created is now supported even when we are sending unreachable
objects to cruft packs.
* "git format-patch --rfc --subject-prefix=<foo>" used to ignore the
"--subject-prefix" option and used "[RFC PATCH]"; now we will add
"RFC" prefix to whatever subject prefix is specified.
* "git log --format" has been taught the %(decorate) placeholder for
further customization over what the "--decorate" option offers.
* The default log message created by "git revert", when reverting a
commit that records a revert, has been tweaked, to encourage people
to describe complex "revert of revert of revert" situations better in
their own words.
* The command-line completion support (in contrib/) learned to
complete "git commit --trailer=" for possible trailer keys.
* "git update-index" learned the "--show-index-version" option to
inspect the index format version used by the on-disk index file.
* "git diff" learned the "diff.statNameWidth" configuration variable,
to give the default width for the name part in the "--stat" output.
* "git range-diff --notes=foo" compared "log --notes=foo --notes" of
the two ranges, instead of using just the specified notes tree,
which has been corrected to use only the specified notes tree.
* The command line completion script (in contrib/) can be told to
complete aliases by including ": git <cmd> ;" in the alias to tell
it that the alias should be completed in a similar way to how "git
<cmd>" is completed. The parsing code for the alias has been
loosened to allow ';' without an extra space before it.
* "git for-each-ref" and friends learned to apply mailmap to
authorname and other fields in a more flexible way than using
separate placeholder letters like %a[eElL] every time we want to
come up with small variants.
* "git repack" machinery learned to pay attention to the "--filter="
option.
* "git repack" learned the "--max-cruft-size" option to prevent cruft
packs from growing without bounds.
* "git merge-tree" learned to take strategy backend specific options
via the "-X" option, like "git merge" does.
* "git log" and friends learned the "--dd" option that is a
short-hand for "--diff-merges=first-parent -p".
* The attribute subsystem learned to honor the "attr.tree"
configuration variable that specifies which tree to read the
.gitattributes files from.
* "git merge-file" learns a mode to read three variants of the
contents to be merged from blob objects.
* see https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.0.txt
Update 2.42.1:
* Fix "git diff" exit code handling
Patchnames
SUSE-SLE-Micro-6.0-48
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for git", "title": "Title of the patch" }, { "category": "description", "text": "This update for git fixes the following issues:\n\ngit was updated to 2.45.1:\n\n * CVE-2024-32002: recursive clones on case-insensitive\n filesystems that support symbolic links are susceptible to case\n confusion (bsc#1224168)\n * CVE-2024-32004: arbitrary code execution during local clones\n (bsc#1224170)\n * CVE-2024-32020: file overwriting vulnerability during local\n clones (bsc#1224171)\n * CVE-2024-32021: git may create hardlinks to arbitrary user-\n readable files (bsc#1224172)\n * CVE-2024-32465: arbitrary code execution during clone operations\n (bsc#1224173)\n\nUpdate to 2.45.0:\n\n * Improved efficiency managing repositories with many references\n (\"git init --ref-format=reftable\")\n * \"git checkout -p\" and friends learned that that \"@\" is a\n synonym for \"HEAD\"\n * cli improvements handling refs\n * Expanded a number of commands and options, UI improvements\n * status.showUntrackedFiles now accepts \"true\"\n * git-cherry-pick(1) now automatically drops redundant commits\n with new --empty option\n * The userdiff patterns for C# has been updated.\n\nUpdate to 2.44.0:\n\n * \"git checkout -B \u003cbranch\u003e\" now longer allows switching to a\n branch that is in use on another worktree. The users need to\n use \"--ignore-other-worktrees\" option.\n * Faster server-side rebases with git replay\n * Faster pack generation with multi-pack reuse\n * rebase auto-squashing now works in non-interactive mode\n * pathspec now understands attr, e.g. \u0027:(attr:~binary) for\n selecting non-binaries, or builtin_objectmode for selecting\n items by file mode or other properties\n * Many other cli UI and internal improvements and extensions\n\n- Do not replace apparmor configuration, fixes bsc#1216545\n\nUpdate to 2.43.2:\n\n * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.2.txt\n * Update to a new feature recently added, \"git show-ref --exists\".\n * Rename detection logic ignored the final line of a file if it\n is an incomplete line.\n * \"git diff --no-rename A B\" did not disable rename detection but\n did not trigger an error from the command line parser.\n * \"git diff --no-index file1 file2\" segfaulted while invoking the\n external diff driver, which has been corrected.\n * A failed \"git tag -s\" did not necessarily result in an error\n depending on the crypto backend, which has been corrected.\n * \"git stash\" sometimes was silent even when it failed due to\n unwritable index file, which has been corrected.\n * Recent conversion to allow more than 0/1 in GIT_FLUSH broke the\n mechanism by flipping what yes/no means by mistake, which has\n been corrected.\n\nUpdate to 2.43.1:\n\n * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.1.txt\n\n- gitweb AppArmor profile: allow reading etc/gitweb-common.conf\n (bsc#1218664)\n\n- git moved to /usr/libexec/git/git, update AppArmor profile\n accordingly (bsc#1218588)\n\nUpdate to 2.43.0:\n\n * The \"--rfc\" option of \"git format-patch\" used to be a valid way to\n override an earlier \"--subject-prefix=\u003csomething\u003e\" on the command\n line and replace it with \"[RFC PATCH]\", but from this release, it\n merely prefixes the string \"RFC \" in front of the given subject\n prefix. If you are negatively affected by this change, please use\n \"--subject-prefix=PATCH --rfc\" as a replacement.\n * In Git 2.42, \"git rev-list --stdin\" learned to take non-revisions\n (like \"--not\") from the standard input, but the way such a \"--not\" was\n handled was quite confusing, which has been rethought. The updated\n rule is that \"--not\" given from the command line only affects revs\n given from the command line that comes but not revs read from the\n standard input, and \"--not\" read from the standard input affects\n revs given from the standard input and not revs given from the\n command line.\n * A message written in olden time prevented a branch from getting\n checked out, saying it is already checked out elsewhere. But these\n days, we treat a branch that is being bisected or rebased just like\n a branch that is checked out and protect it from getting modified\n with the same codepath. The message has been rephrased to say that\n the branch is \"in use\" to avoid confusion.\n * Hourly and other schedules of \"git maintenance\" jobs are randomly\n distributed now.\n * \"git cmd -h\" learned to signal which options can be negated by\n listing such options like \"--[no-]opt\".\n * The way authentication related data other than passwords (e.g.,\n oauth token and password expiration data) are stored in libsecret\n keyrings has been rethought.\n * Update the libsecret and wincred credential helpers to correctly\n match which credential to erase; they erased the wrong entry in\n some cases.\n * Git GUI updates.\n * \"git format-patch\" learned a new \"--description-file\" option that\n lets cover letter description to be fed; this can be used on\n detached HEAD where there is no branch description available, and\n also can override the branch description if there is one.\n * Use of the \"--max-pack-size\" option to allow multiple packfiles to\n be created is now supported even when we are sending unreachable\n objects to cruft packs.\n * \"git format-patch --rfc --subject-prefix=\u003cfoo\u003e\" used to ignore the\n \"--subject-prefix\" option and used \"[RFC PATCH]\"; now we will add\n \"RFC\" prefix to whatever subject prefix is specified.\n * \"git log --format\" has been taught the %(decorate) placeholder for\n further customization over what the \"--decorate\" option offers.\n * The default log message created by \"git revert\", when reverting a\n commit that records a revert, has been tweaked, to encourage people\n to describe complex \"revert of revert of revert\" situations better in\n their own words.\n * The command-line completion support (in contrib/) learned to\n complete \"git commit --trailer=\" for possible trailer keys.\n * \"git update-index\" learned the \"--show-index-version\" option to\n inspect the index format version used by the on-disk index file.\n * \"git diff\" learned the \"diff.statNameWidth\" configuration variable,\n to give the default width for the name part in the \"--stat\" output.\n * \"git range-diff --notes=foo\" compared \"log --notes=foo --notes\" of\n the two ranges, instead of using just the specified notes tree,\n which has been corrected to use only the specified notes tree.\n * The command line completion script (in contrib/) can be told to\n complete aliases by including \": git \u003ccmd\u003e ;\" in the alias to tell\n it that the alias should be completed in a similar way to how \"git\n \u003ccmd\u003e\" is completed. The parsing code for the alias has been\n loosened to allow \u0027;\u0027 without an extra space before it.\n * \"git for-each-ref\" and friends learned to apply mailmap to\n authorname and other fields in a more flexible way than using\n separate placeholder letters like %a[eElL] every time we want to\n come up with small variants.\n * \"git repack\" machinery learned to pay attention to the \"--filter=\"\n option.\n * \"git repack\" learned the \"--max-cruft-size\" option to prevent cruft\n packs from growing without bounds.\n * \"git merge-tree\" learned to take strategy backend specific options\n via the \"-X\" option, like \"git merge\" does.\n * \"git log\" and friends learned the \"--dd\" option that is a\n short-hand for \"--diff-merges=first-parent -p\".\n * The attribute subsystem learned to honor the \"attr.tree\"\n configuration variable that specifies which tree to read the\n .gitattributes files from.\n * \"git merge-file\" learns a mode to read three variants of the\n contents to be merged from blob objects.\n * see https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.0.txt\n\nUpdate 2.42.1:\n\n * Fix \"git diff\" exit code handling\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-SLE-Micro-6.0-48", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_20049-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2025:20049-1", "url": "https://www.suse.com/support/update/announcement/2025/suse-su-202520049-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2025:20049-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2025-June/021288.html" }, { "category": "self", "summary": "SUSE Bug 1042640", "url": "https://bugzilla.suse.com/1042640" }, { "category": "self", "summary": "SUSE Bug 1061041", "url": "https://bugzilla.suse.com/1061041" }, { "category": "self", "summary": "SUSE Bug 1069468", "url": "https://bugzilla.suse.com/1069468" }, { "category": "self", "summary": "SUSE Bug 1082023", "url": "https://bugzilla.suse.com/1082023" }, { "category": "self", "summary": "SUSE Bug 1216545", "url": "https://bugzilla.suse.com/1216545" }, { "category": "self", "summary": "SUSE Bug 1218588", "url": "https://bugzilla.suse.com/1218588" }, { "category": "self", "summary": "SUSE Bug 1218664", "url": "https://bugzilla.suse.com/1218664" }, { "category": "self", "summary": "SUSE Bug 1224168", "url": "https://bugzilla.suse.com/1224168" }, { "category": "self", "summary": "SUSE Bug 1224170", "url": "https://bugzilla.suse.com/1224170" }, { "category": "self", "summary": "SUSE Bug 1224171", "url": "https://bugzilla.suse.com/1224171" }, { "category": "self", "summary": "SUSE Bug 1224172", "url": "https://bugzilla.suse.com/1224172" }, { "category": "self", "summary": "SUSE Bug 1224173", "url": "https://bugzilla.suse.com/1224173" }, { "category": "self", "summary": "SUSE Bug 779536", "url": "https://bugzilla.suse.com/779536" }, { "category": "self", "summary": "SUSE CVE CVE-2005-4900 page", "url": "https://www.suse.com/security/cve/CVE-2005-4900/" }, { "category": "self", "summary": "SUSE CVE CVE-2017-14867 page", "url": "https://www.suse.com/security/cve/CVE-2017-14867/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-32002 page", "url": "https://www.suse.com/security/cve/CVE-2024-32002/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-32004 page", "url": "https://www.suse.com/security/cve/CVE-2024-32004/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-32020 page", "url": "https://www.suse.com/security/cve/CVE-2024-32020/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-32021 page", "url": "https://www.suse.com/security/cve/CVE-2024-32021/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-32465 page", "url": "https://www.suse.com/security/cve/CVE-2024-32465/" } ], "title": "Security update for git", "tracking": { "current_release_date": "2025-02-03T08:55:36Z", "generator": { "date": "2025-02-03T08:55:36Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2025:20049-1", "initial_release_date": "2025-02-03T08:55:36Z", "revision_history": [ { "date": "2025-02-03T08:55:36Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "git-2.45.1-1.1.aarch64", "product": { "name": "git-2.45.1-1.1.aarch64", "product_id": "git-2.45.1-1.1.aarch64" } }, { "category": "product_version", "name": "git-core-2.45.1-1.1.aarch64", "product": { "name": "git-core-2.45.1-1.1.aarch64", "product_id": "git-core-2.45.1-1.1.aarch64" } }, { "category": "product_version", "name": "perl-Git-2.45.1-1.1.aarch64", "product": { "name": "perl-Git-2.45.1-1.1.aarch64", "product_id": "perl-Git-2.45.1-1.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "git-2.45.1-1.1.s390x", "product": { "name": "git-2.45.1-1.1.s390x", "product_id": "git-2.45.1-1.1.s390x" } }, { "category": "product_version", "name": "git-core-2.45.1-1.1.s390x", "product": { "name": "git-core-2.45.1-1.1.s390x", "product_id": "git-core-2.45.1-1.1.s390x" } }, { "category": "product_version", "name": "perl-Git-2.45.1-1.1.s390x", "product": { "name": "perl-Git-2.45.1-1.1.s390x", "product_id": "perl-Git-2.45.1-1.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "git-2.45.1-1.1.x86_64", "product": { "name": "git-2.45.1-1.1.x86_64", "product_id": "git-2.45.1-1.1.x86_64" } }, { "category": "product_version", "name": "git-core-2.45.1-1.1.x86_64", "product": { "name": "git-core-2.45.1-1.1.x86_64", "product_id": "git-core-2.45.1-1.1.x86_64" } }, { "category": "product_version", "name": "perl-Git-2.45.1-1.1.x86_64", "product": { "name": "perl-Git-2.45.1-1.1.x86_64", "product_id": "perl-Git-2.45.1-1.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Micro 6.0", "product": { "name": "SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0", "product_identification_helper": { "cpe": "cpe:/o:suse:sl-micro:6.0" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "git-2.45.1-1.1.aarch64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64" }, "product_reference": "git-2.45.1-1.1.aarch64", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "git-2.45.1-1.1.s390x as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x" }, "product_reference": "git-2.45.1-1.1.s390x", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "git-2.45.1-1.1.x86_64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64" }, "product_reference": "git-2.45.1-1.1.x86_64", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.45.1-1.1.aarch64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64" }, "product_reference": "git-core-2.45.1-1.1.aarch64", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.45.1-1.1.s390x as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x" }, "product_reference": "git-core-2.45.1-1.1.s390x", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "git-core-2.45.1-1.1.x86_64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64" }, "product_reference": "git-core-2.45.1-1.1.x86_64", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.45.1-1.1.aarch64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64" }, "product_reference": "perl-Git-2.45.1-1.1.aarch64", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.45.1-1.1.s390x as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x" }, "product_reference": "perl-Git-2.45.1-1.1.s390x", "relates_to_product_reference": "SUSE Linux Micro 6.0" }, { "category": "default_component_of", "full_product_name": { "name": "perl-Git-2.45.1-1.1.x86_64 as component of SUSE Linux Micro 6.0", "product_id": "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" }, "product_reference": "perl-Git-2.45.1-1.1.x86_64", "relates_to_product_reference": "SUSE Linux Micro 6.0" } ] }, "vulnerabilities": [ { "cve": "CVE-2005-4900", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2005-4900" } ], "notes": [ { "category": "general", "text": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2005-4900", "url": "https://www.suse.com/security/cve/CVE-2005-4900" }, { "category": "external", "summary": "SUSE Bug 1026646 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026646" }, { "category": "external", "summary": "SUSE Bug 1026936 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1026936" }, { "category": "external", "summary": "SUSE Bug 1042640 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1042640" }, { "category": "external", "summary": "SUSE Bug 1150998 for CVE-2005-4900", "url": "https://bugzilla.suse.com/1150998" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "moderate" } ], "title": "CVE-2005-4900" }, { "cve": "CVE-2017-14867", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-14867" } ], "notes": [ { "category": "general", "text": "Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-14867", "url": "https://www.suse.com/security/cve/CVE-2017-14867" }, { "category": "external", "summary": "SUSE Bug 1060377 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1060377" }, { "category": "external", "summary": "SUSE Bug 1060378 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1060378" }, { "category": "external", "summary": "SUSE Bug 1061041 for CVE-2017-14867", "url": "https://bugzilla.suse.com/1061041" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "important" } ], "title": "CVE-2017-14867" }, { "cve": "CVE-2024-32002", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-32002" } ], "notes": [ { "category": "general", "text": "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule\u0027s worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won\u0027t work. As always, it is best to avoid cloning repositories from untrusted sources.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-32002", "url": "https://www.suse.com/security/cve/CVE-2024-32002" }, { "category": "external", "summary": "SUSE Bug 1224168 for CVE-2024-32002", "url": "https://bugzilla.suse.com/1224168" }, { "category": "external", "summary": "SUSE Bug 1224170 for CVE-2024-32002", "url": "https://bugzilla.suse.com/1224170" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "important" } ], "title": "CVE-2024-32002" }, { "cve": "CVE-2024-32004", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-32004" } ], "notes": [ { "category": "general", "text": "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-32004", "url": "https://www.suse.com/security/cve/CVE-2024-32004" }, { "category": "external", "summary": "SUSE Bug 1224170 for CVE-2024-32004", "url": "https://bugzilla.suse.com/1224170" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "important" } ], "title": "CVE-2024-32004" }, { "cve": "CVE-2024-32020", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-32020" } ], "notes": [ { "category": "general", "text": "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository\u0027s object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a \"proper\" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-32020", "url": "https://www.suse.com/security/cve/CVE-2024-32020" }, { "category": "external", "summary": "SUSE Bug 1224171 for CVE-2024-32020", "url": "https://bugzilla.suse.com/1224171" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.9, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L", "version": "3.1" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "moderate" } ], "title": "CVE-2024-32020" }, { "cve": "CVE-2024-32021", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-32021" } ], "notes": [ { "category": "general", "text": "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository\u0027s `objects/` directory. When cloning a repository over the filesystem (without explicitly specifying the `file://` protocol or `--no-local`), the optimizations for local cloning\nwill be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-32021", "url": "https://www.suse.com/security/cve/CVE-2024-32021" }, { "category": "external", "summary": "SUSE Bug 1224172 for CVE-2024-32021", "url": "https://bugzilla.suse.com/1224172" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.9, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L", "version": "3.1" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "moderate" } ], "title": "CVE-2024-32021" }, { "cve": "CVE-2024-32465", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-32465" } ], "notes": [ { "category": "general", "text": "Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-32465", "url": "https://www.suse.com/security/cve/CVE-2024-32465" }, { "category": "external", "summary": "SUSE Bug 1224170 for CVE-2024-32465", "url": "https://bugzilla.suse.com/1224170" }, { "category": "external", "summary": "SUSE Bug 1224173 for CVE-2024-32465", "url": "https://bugzilla.suse.com/1224173" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Micro 6.0:git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:git-core-2.45.1-1.1.x86_64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.aarch64", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.s390x", "SUSE Linux Micro 6.0:perl-Git-2.45.1-1.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-02-03T08:55:36Z", "details": "important" } ], "title": "CVE-2024-32465" } ] }
gsd-2005-4900
Vulnerability from gsd
Modified
2023-12-13 01:20
Details
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2005-4900", "description": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "id": "GSD-2005-4900", "references": [ "https://www.suse.com/security/cve/CVE-2005-4900.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2005-4900" ], "details": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "id": "GSD-2005-4900", "modified": "2023-12-13T01:20:09.924663Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2005-4900", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://sites.google.com/site/itstheshappening", "refsource": "MISC", "url": "https://sites.google.com/site/itstheshappening" }, { "name": "12577", "refsource": "BID", "url": "http://www.securityfocus.com/bid/12577" }, { "name": "http://shattered.io/", "refsource": "MISC", "url": "http://shattered.io/" }, { "name": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html", "refsource": "MISC", "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "name": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1", "refsource": "MISC", "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "name": "http://ia.cr/2007/474", "refsource": "MISC", "url": "http://ia.cr/2007/474" }, { "name": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html", "refsource": "MISC", "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "name": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html", "refsource": "MISC", "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "name": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html", "refsource": "MISC", "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "name": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/", "refsource": "MISC", "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "name": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340", "refsource": "CONFIRM", "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "47.0.2526.111", "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2005-4900" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-326" } ] } ] }, "references": { "reference_data": [ { "name": "http://ia.cr/2007/474", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "http://ia.cr/2007/474" }, { "name": "https://sites.google.com/site/itstheshappening", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://sites.google.com/site/itstheshappening" }, { "name": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "name": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "name": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "name": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html", "refsource": "MISC", "tags": [], "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "name": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/", "refsource": "MISC", "tags": [], "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/" }, { "name": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1", "refsource": "MISC", "tags": [], "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "name": "http://shattered.io/", "refsource": "MISC", "tags": [], "url": "http://shattered.io/" }, { "name": "12577", "refsource": "BID", "tags": [], "url": "http://www.securityfocus.com/bid/12577" }, { "name": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340", "refsource": "CONFIRM", "tags": [], "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.9, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "exploitabilityScore": 2.2, "impactScore": 3.6 } }, "lastModifiedDate": "2020-12-09T09:15Z", "publishedDate": "2016-10-14T16:59Z" } } }
ghsa-xj59-9qjv-fr54
Vulnerability from github
Published
2022-05-01 02:31
Modified
2025-04-12 13:05
Severity ?
VLAI Severity ?
Details
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
{ "affected": [], "aliases": [ "CVE-2005-4900" ], "database_specific": { "cwe_ids": [ "CWE-326" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2016-10-14T16:59:00Z", "severity": "MODERATE" }, "details": "SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.", "id": "GHSA-xj59-9qjv-fr54", "modified": "2025-04-12T13:05:40Z", "published": "2022-05-01T02:31:49Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-4900" }, { "type": "WEB", "url": "https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead" }, { "type": "WEB", "url": "https://kc.mcafee.com/corporate/index?page=content\u0026id=SB10340" }, { "type": "WEB", "url": "https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html" }, { "type": "WEB", "url": "https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html" }, { "type": "WEB", "url": "https://sites.google.com/site/itstheshappening" }, { "type": "WEB", "url": "https://www.schneier.com/blog/archives/2005/02/sha1_broken.html" }, { "type": "WEB", "url": "https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html" }, { "type": "WEB", "url": "http://ia.cr/2007/474" }, { "type": "WEB", "url": "http://shattered.io" }, { "type": "WEB", "url": "http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/12577" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "type": "CVSS_V3" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…