Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
openSUSE:Step:15-SP4
patchinfo.9607
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.9607
<patchinfo incident="9607"> <issue tracker="bnc" id="1114729">VUL-0: libgit2: various string-to-integer and buffer handling issues fixed in 0.27.6, 0.26.8</issue> <issue tracker="bnc" id="1110949">VUL-0: CVE-2018-17456: git,libgit2: arbitrary code execution via .gitmodules</issue> <issue tracker="cve" id="2018-17456"/> <category>security</category> <rating>important</rating> <packager>mgorse</packager> <description>This update for libgit2 fixes the following issues: Security issue fixed: - CVE-2018-17456: Submodule URLs and paths with a leading "-" are now ignored to avoid injecting options into library consumers that perform recursive clones (bsc#1110949). Non-security issues fixed: - Version update to version 0.26.8 (bsc#1114729). - Full changelog can be found at: * https://github.com/libgit2/libgit2/releases/tag/v0.26.8 * https://github.com/libgit2/libgit2/releases/tag/v0.26.7 </description> <summary>Security update for libgit2</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor