USN-7207-1: Git vulnerabilities
It was discovered that Git incorrectly handled certain URLs when asking for credentials. An attacker could possibly use this issue to mislead the user into typing passwords for trusted sites that would then be sent to untrusted sites instead. (CVE-2024-50349) It was discovered that git incorrectly handled line endings when using credential helpers. (CVE-2024-52006)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7207-1?
USN-7207-1 is considered a significant vulnerability that can lead to credential misdirection.
How do I fix USN-7207-1?
To fix USN-7207-1, upgrade Git to the specified remedied versions in the advisory for your Ubuntu release.
What versions of Git are affected by USN-7207-1?
USN-7207-1 affects multiple versions of Git prior to the remedied versions listed in the advisory.
Can USN-7207-1 be exploited remotely?
Yes, USN-7207-1 can potentially be exploited by an attacker who misleads the user into entering credentials.
What systems are impacted by USN-7207-1?
USN-7207-1 specifically impacts Ubuntu 24.10, 24.04, and 22.04 installations that run the vulnerable versions of Git.