Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Tue, 20 Jan 2009 10:11:58 +0100
From: Sebastian Krahmer <krahmer@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request -- git

On Tue, Jan 20, 2009 at 09:02:31AM +0100, Tomas Hoger wrote:

> No, they have not.  They fixed both -5516 (git_search) and -5517
> (git_snapshot and git_object) issues using quote_command() (in their
> git-1.5.2.4-24.4.src.rpm).  No idea why only one of the CVEs was
> mentioned in the security report...  They don't seem to include any
> patch for diff.external issue, or claim to have fixed it.
Only opensuse 11.0 and 11.1 were affected by diff.external
issue and packages have been released for that.
opensuse 10.3 was only affected by the remote hole and
not by diff.external. packages were already released, too.

Sebastian

-- 
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer@...e.de - SuSE Security Team
~ SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux