MGASA-2025-0016 - Updated git packages fix security vulnerabilities

Publication date: 20 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0016.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-50349,
     CVE-2024-52006

Git does not sanitize URLs when asking for credentials interactively.
(CVE-2024-50349)
Newline confusion in credential helpers can lead to credential
exfiltration in git. (CVE-2024-52006)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33921
- https://www.openwall.com/lists/oss-security/2025/01/14/4
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50349
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52006

SRPMS:
- 9/core/git-2.41.3-1.mga9

Mageia 2025-0016: git Security Advisory Updates

Git does not sanitize URLs when asking for credentials interactively

Summary

Git does not sanitize URLs when asking for credentials interactively. (CVE-2024-50349) Newline confusion in credential helpers can lead to credential exfiltration in git. (CVE-2024-52006)

References

- https://bugs.mageia.org/show_bug.cgi?id=33921

- https://www.openwall.com/lists/oss-security/2025/01/14/4

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50349

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52006

Resolution

MGASA-2025-0016 - Updated git packages fix security vulnerabilities

SRPMS

- 9/core/git-2.41.3-1.mga9

Severity
Publication date: 20 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0016.html
Type: security
CVE: CVE-2024-50349, CVE-2024-52006

Related News