From patchwork Sun May 24 20:24:34 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Korsgaard X-Patchwork-Id: 1296951 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.137; helo=fraxinus.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=korsgaard.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=kyePMRR+; dkim-atps=neutral Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 49VWvL5X7wz9sRW for ; Mon, 25 May 2020 06:25:50 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id B329485FA0; Sun, 24 May 2020 20:25:46 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l_TuS5PYZROc; Sun, 24 May 2020 20:25:44 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by fraxinus.osuosl.org (Postfix) with ESMTP id 8199685C4A; Sun, 24 May 2020 20:25:44 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id 4471D1BF3EA for ; Sun, 24 May 2020 20:25:42 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 2822E2154A for ; Sun, 24 May 2020 20:25:42 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a6qy9OZ13cQM for ; Sun, 24 May 2020 20:25:40 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-ed1-f65.google.com (mail-ed1-f65.google.com [209.85.208.65]) by silver.osuosl.org (Postfix) with ESMTPS id 093111FEAE for ; Sun, 24 May 2020 20:25:40 +0000 (UTC) Received: by mail-ed1-f65.google.com with SMTP id l25so13477633edj.4 for ; Sun, 24 May 2020 13:25:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=RAct0UcfwF1QhUUHKWyN8jGNVLstFvS1pmMmLpiPjhU=; b=kyePMRR+6X6j4vSPIxsVbwmaC/0KIt0hcPFCcTEVsRmKTLQQL+yvaUV0CVVlwa5LK0 yVJ0BcHdMUBPVtQZyZGwYUAZ8rDYkhfAhH8BYzVZZ58ZBuwwu9qzdPfqOp+Lx/OwfsDg 2CR4SH6mit+I27W+zn08x5mFjKAS2o0wOrvL/aR32xTc6Wkc8aUhaj3pvvE0mS7Bs506 +kbyHk62hNxw8oU26QQtu53A6nUo07eTcNdXdThYwsKspL3j5yt3rknYfrZrv3hJIv5+ qGIb+nQcRowFkXx9HA3eQ4v5T9sLvtgYjt2yRyLKy1gpPQRA5bNforqlusOyT5g+e6G+ OXtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :mime-version:content-transfer-encoding; bh=RAct0UcfwF1QhUUHKWyN8jGNVLstFvS1pmMmLpiPjhU=; b=nSR+Wr9dJq/A10JLIXjIPUI/ZHdiA5t1jFiIAi12NoLSsa78M62gsYKNDU9WCCM+Qy Cm9QFZfNbMEdoWaIhcvFmGhZMpq7gbyauNkxzMVYxHqL3aE3LQ9ktfmMj3+cIuwZKgwX NeVhxYNoeSbQwC7fZzkicVAg6XEocE/i+eBlM91H26NVvNSQ4OHMeQ13qYBF7tUeYEHp VFYR0RcVXmpZEVkpoJwZDvMaN8oysSR24ztiLI10rSDfP8Iat8lJjl0PFIwcVIJx1yLH s0y15MHT+289goMugQEhpT+Debt5OVPFVEZebzE6+C4TXkeusq4pq1mM/hY6uOsXmdd4 Yuyw== X-Gm-Message-State: AOAM533GVsy/bxQPkYPn6B1/Cpz7Nhs6y0Qidebd3kH3fJ/Hv0rT3We5 dYyLFhKWVeeLDyYc01dZJJR82oFg X-Google-Smtp-Source: ABdhPJy6RrmH4IPmBRZu5jg9nQLuHIGHlk9OA8YirJ6QkI8v73QyOBtPxTCSy5R4ttc75zhUQsGBxQ== X-Received: by 2002:a50:ec8d:: with SMTP id e13mr12956085edr.8.1590351938099; Sun, 24 May 2020 13:25:38 -0700 (PDT) Received: from dell.be.48ers.dk (d51A5BC31.access.telenet.be. [81.165.188.49]) by smtp.gmail.com with ESMTPSA id s7sm14257846edg.73.2020.05.24.13.25.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 24 May 2020 13:25:37 -0700 (PDT) Received: from peko by dell.be.48ers.dk with local (Exim 4.92) (envelope-from ) id 1jcxBg-000868-QF; Sun, 24 May 2020 22:25:36 +0200 From: Peter Korsgaard To: buildroot@buildroot.org Date: Sun, 24 May 2020 22:24:34 +0200 Message-Id: <20200524202435.30964-1-peter@korsgaard.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Subject: [Buildroot] [PATCH-2020.02.x] package/git: security bump to version 2.24.3 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Matt Weber , Peter Korsgaard Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Fixes the following security issues: * (2.24.2) With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol. * (2.24.3) With a crafted URL that contains a newline or empty host, or lacks a scheme, the credential helper machinery can be fooled into providing credential information that is not appropriate for the protocol in use and host being contacted. Unlike the vulnerability CVE-2020-5260 fixed in v2.17.4, the credentials are not for a host of the attacker's choosing; instead, they are for some unspecified host (based on how the configured credential helper handles an absent "host" parameter). The attack has been made impossible by refusing to work with under-specified credential patterns. Signed-off-by: Peter Korsgaard --- package/git/git.hash | 2 +- package/git/git.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/git/git.hash b/package/git/git.hash index 74bf334b78..5734fea175 100644 --- a/package/git/git.hash +++ b/package/git/git.hash @@ -1,4 +1,4 @@ # From: https://www.kernel.org/pub/software/scm/git/sha256sums.asc -sha256 723f24dce8fdd621a308b6187553fce7d5244205c065fe0a3aebd0b7c3f88562 git-2.24.1.tar.xz +sha256 da8c594c21ef965cdff427f27a7a384833d96d4d67f3a13915b498009646ef29 git-2.24.3.tar.xz sha256 5b2198d1645f767585e8a88ac0499b04472164c0d2da22e75ecf97ef443ab32e COPYING sha256 1922f45d2c49e390032c9c0ba6d7cac904087f7cec51af30c2b2ad022ce0e76a LGPL-2.1 diff --git a/package/git/git.mk b/package/git/git.mk index dd79c41e4a..d5e81b529c 100644 --- a/package/git/git.mk +++ b/package/git/git.mk @@ -4,7 +4,7 @@ # ################################################################################ -GIT_VERSION = 2.24.1 +GIT_VERSION = 2.24.3 GIT_SOURCE = git-$(GIT_VERSION).tar.xz GIT_SITE = $(BR2_KERNEL_MIRROR)/software/scm/git GIT_LICENSE = GPL-2.0, LGPL-2.1+