USN-4334-1: Git vulnerability
Carlo Arenas discovered that Git incorrectly handled certain URLs containing newlines, empty hosts, or lacking a scheme. A remote attacker could possibly use this issue to trick Git into returning credential information for a wrong host.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Git vulnerability?
The vulnerability ID for this Git vulnerability is USN-4334-1.
What is the impact of this vulnerability?
This vulnerability could allow a remote attacker to trick Git into returning credential information for a wrong host.
Which versions of Git are affected by this vulnerability?
The versions affected by this vulnerability are 2.20.1-2ubuntu1.19.10.3, 2.17.1-1ubuntu0.7, and 2.7.4-0ubuntu1.9.
How can I fix this vulnerability?
To fix this vulnerability, update Git to version 2.20.1-2ubuntu1.19.10.3, 2.17.1-1ubuntu0.7, or 2.7.4-0ubuntu1.9 depending on your Ubuntu version.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu Security Notice USN-4334-1 page.