ELA-223-1 git security update

information disclosure

2020-04-15
Packagegit
Version1:1.7.10.4-1+wheezy9
Related CVE CVE-2020-5260

Felix Wilhelm of Google Project Zero discovered a flaw in git, a fast, scalable, distributed revision control system. With a crafted URL that contains a newline, the credential helper machinery can be fooled to return credential information for a wrong host.

For Debian 7 Wheezy, these problems have been fixed in version 1:1.7.10.4-1+wheezy9.

We recommend that you upgrade your git packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/