MGASA-2021-0137

Source
https://advisories.mageia.org/MGASA-2021-0137.html
Import Source
https://advisories.mageia.org/MGASA-2021-0137.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0137
Related
Published
2021-03-14T21:20:42Z
Modified
2021-03-14T20:30:26Z
Summary
Updated git packages fix a security vulnerability
Details

On case-insensitive file systems with support for symbolic links, if Git is configured globally to apply delay-capable clean/smudge filters (such as Git LFS), Git could be fooled into running remote code during a clone (CVE-2021-21300).

References
Credits

Affected packages

Mageia:7 / git

Package

Name
git
Purl
pkg:rpm/mageia/git?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.21.4-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / git

Package

Name
git
Purl
pkg:rpm/mageia/git?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.30.2-1.mga8

Ecosystem specific

{
    "section": "core"
}