Slackware: 2022-291-01: git Security Update
Summary
Here are the details from the Slackware 15.0 ChangeLog: patches/packages/git-2.35.5-i586-1_slack15.0.txz: Upgraded. This release fixes two security issues: * CVE-2022-39253: When relying on the `--local` clone optimization, Git dereferences symbolic links in the source repository before creating hardlinks (or copies) of the dereferenced link in the destination repository. This can lead to surprising behavior where arbitrary files are present in a repository's `$GIT_DIR` when cloning from a malicious repository. Git will no longer dereference symbolic links via the `--local` clone mechanism, and will instead refuse to clone repositories that have symbolic links present in the `$GIT_DIR/objects` directory. Additionally, the value of `protocol.file.allow` is changed to be "user" by default. * CVE-2022-39260: An overly-long command string given to `git shell` can result in overflow in `split_cmdline()`, leading to arbitrary heap writes and remote code ...
Where Find New Packages
Thanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:
MD5 Signatures
Slackware 14.0 package:
48ee1ee2b38d78db02f8a071685b9450 git-2.30.6-i486-1_slack14.0.txz
Slackware x86_64 14.0 package:
e28b635209f0609c6ef18e114a88fc16 git-2.30.6-x86_64-1_slack14.0.txz
Slackware 14.1 package:
1ad7ec8d222bbb240485dd62db3adf40 git-2.30.6-i486-1_slack14.1.txz
Slackware x86_64 14.1 package:
334f2f6a9eda3bb9a242d91fc40b97d4 git-2.30.6-x86_64-1_slack14.1.txz
Slackware 14.2 package:
346f1b5332fc9fa6c256578c6d2296f3 git-2.30.6-i586-1_slack14.2.txz
Slackware x86_64 14.2 package:
385741384f10e345bf736489096c7f63 git-2.30.6-x86_64-1_slack14.2.txz
Slackware 15.0 package:
c36b2529a04298271a42b54a2e22cd7c git-2.35.5-i586-1_slack15.0.txz
Slackware x86_64 15.0 package:
cf2c3403da6faf885008e4fa7f9ff5c4 git-2.35.5-x86_64-1_slack15.0.txz
Slackware -current package:
44fd8361f0920419437471089a87e984 d/git-2.38.1-i586-1.txz
Slackware x86_64 -current package:
09bd553a683015bdcd1549ff4465d704 d/git-2.38.1-x86_64-1.txz
Installation Instructions
Installation instructions: Upgrade the package as root: # upgradepkg git-2.35.5-i586-1_slack15.0.txz