[Git][security-tracker-team/security-tracker][master] Add CVE-2022-24765/git

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Apr 13 06:49:57 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c528076f by Salvatore Bonaccorso at 2022-04-13T07:40:16+02:00
Add CVE-2022-24765/git

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11664,7 +11664,15 @@ CVE-2022-24766 (mitmproxy is an interactive, SSL/TLS-capable intercepting proxy.
 	NOTE: https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-gcx2-gvj7-pxv3
 	NOTE: https://github.com/mitmproxy/mitmproxy/commit/b06fb6d157087d526bd02e7aadbe37c56865c71b (v8.0.0)
 CVE-2022-24765 (Git for Windows is a fork of Git containing Windows-specific patches.  ...)
-	TODO: check
+	- git 1:2.35.2-1
+	NOTE: https://github.com/git/git/commit/6e7ad1e4c22e7038975ba37c7413374fe566b064 (v2.30.3)
+	NOTE: https://github.com/git/git/commit/bdc77d1d685be9c10b88abb281a42bc620548595 (v2.30.3)
+	NOTE: https://github.com/git/git/commit/8959555cee7ec045958f9b6dd62e541affb7e7d9 (v2.30.3)
+	NOTE: https://github.com/git/git/commit/fdcad5a53e14bd397e4fa323e7fd0c3bf16dd373 (v2.30.3)
+	NOTE: https://github.com/git/git/commit/cb95038137e9e66fc6a6b4a0e8db62bcc521b709 (v2.30.3)
+	NOTE: https://lore.kernel.org/git/xmqqv8veb5i6.fsf@gitster.g/
+	NOTE: Limitations of ownership checking for the CVE fix:
+	NOTE: https://lore.kernel.org/git/CAKJfoCEgiNvQJGt=rGYTaKQ1i2ihrPmX2Sz3Zxg-y66L+1Qh6g@mail.gmail.com/
 CVE-2022-24764 (PJSIP is a free and open source multimedia communication library writt ...)
 	{DLA-2962-1}
 	- pjproject <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c528076f068bf32c69c7d08bcb4fec0e9430771b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c528076f068bf32c69c7d08bcb4fec0e9430771b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220413/0c8efbe9/attachment.htm>


More information about the debian-security-tracker-commits mailing list