Security update for git
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:0802-1
Final
1
1
2016-03-17T10:45:12Z
current
2016-03-17T10:45:12Z
2016-03-17T10:45:12Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for git
This update for git fixes a buffer overflow issue that had the potential to be
abused for remote execution of arbitrary code (CVE-2016-2315, CVE-2016-2324,
bsc#971328).
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.html
E-Mail link for openSUSE-SU-2016:0802-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
openSUSE Leap 42.1
git-2.6.2-3.1
git-arch-2.6.2-3.1
git-core-2.6.2-3.1
git-credential-gnome-keyring-2.6.2-3.1
git-cvs-2.6.2-3.1
git-daemon-2.6.2-3.1
git-doc-2.6.2-3.1
git-email-2.6.2-3.1
git-gui-2.6.2-3.1
git-svn-2.6.2-3.1
git-web-2.6.2-3.1
gitk-2.6.2-3.1
git-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-arch-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-core-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-credential-gnome-keyring-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-cvs-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-daemon-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-doc-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-email-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-gui-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-svn-2.6.2-3.1 as a component of openSUSE Leap 42.1
git-web-2.6.2-3.1 as a component of openSUSE Leap 42.1
gitk-2.6.2-3.1 as a component of openSUSE Leap 42.1
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVE-2016-2315
openSUSE Leap 42.1:git-2.6.2-3.1
openSUSE Leap 42.1:git-arch-2.6.2-3.1
openSUSE Leap 42.1:git-core-2.6.2-3.1
openSUSE Leap 42.1:git-credential-gnome-keyring-2.6.2-3.1
openSUSE Leap 42.1:git-cvs-2.6.2-3.1
openSUSE Leap 42.1:git-daemon-2.6.2-3.1
openSUSE Leap 42.1:git-doc-2.6.2-3.1
openSUSE Leap 42.1:git-email-2.6.2-3.1
openSUSE Leap 42.1:git-gui-2.6.2-3.1
openSUSE Leap 42.1:git-svn-2.6.2-3.1
openSUSE Leap 42.1:git-web-2.6.2-3.1
openSUSE Leap 42.1:gitk-2.6.2-3.1
moderate
Please Install the update.
https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.html
https://www.suse.com/security/cve/CVE-2016-2315.html
CVE-2016-2315
https://bugzilla.suse.com/971328
SUSE Bug 971328
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
CVE-2016-2324
openSUSE Leap 42.1:git-2.6.2-3.1
openSUSE Leap 42.1:git-arch-2.6.2-3.1
openSUSE Leap 42.1:git-core-2.6.2-3.1
openSUSE Leap 42.1:git-credential-gnome-keyring-2.6.2-3.1
openSUSE Leap 42.1:git-cvs-2.6.2-3.1
openSUSE Leap 42.1:git-daemon-2.6.2-3.1
openSUSE Leap 42.1:git-doc-2.6.2-3.1
openSUSE Leap 42.1:git-email-2.6.2-3.1
openSUSE Leap 42.1:git-gui-2.6.2-3.1
openSUSE Leap 42.1:git-svn-2.6.2-3.1
openSUSE Leap 42.1:git-web-2.6.2-3.1
openSUSE Leap 42.1:gitk-2.6.2-3.1
moderate
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Please Install the update.
https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.html
https://www.suse.com/security/cve/CVE-2016-2324.html
CVE-2016-2324
https://bugzilla.suse.com/971328
SUSE Bug 971328