[Git][security-tracker-team/security-tracker][master] Mark now git as no-dsa for trixie and bookworm
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 15 19:10:13 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a588ca12 by Salvatore Bonaccorso at 2025-08-15T20:09:47+02:00
Mark now git as no-dsa for trixie and bookworm
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11363,16 +11363,22 @@ CVE-2025-48386 (Git is a fast, scalable, distributed revision control system wit
NOTE: Fixed by: https://github.com/git/git/commit/9de345cb273cc7faaeda279c7e07149d8a15a319 (v2.43.7)
CVE-2025-48385 (Git is a fast, scalable, distributed revision control system with an u ...)
- git 1:2.50.1-0.1 (bug #1108983)
+ [trixie] - git <no-dsa> (Will be fixed in point release)
+ [bookworm] - git <no-dsa> (Will be fixed in point release)
NOTE: https://github.com/git/git/security/advisories/GHSA-m98c-vgpc-9655
NOTE: https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
NOTE: Fixed by: https://github.com/git/git/commit/35cb1bb0b92c132249d932c05bbd860d410e12d4 (v2.43.7)
CVE-2025-48384 (Git is a fast, scalable, distributed revision control system with an u ...)
- git 1:2.50.1-0.1 (bug #1108983)
+ [trixie] - git <no-dsa> (Will be fixed in point release)
+ [bookworm] - git <no-dsa> (Will be fixed in point release)
NOTE: https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
NOTE: https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
NOTE: Fixed by: https://github.com/git/git/commit/05e9cd64ee23bbadcea6bcffd6660ed02b8eab89 (2.43.7)
CVE-2025-46835 (Git GUI allows you to use the Git source control management tools via ...)
- git 1:2.50.1-0.1 (bug #1108983)
+ [trixie] - git <no-dsa> (Will be fixed in point release)
+ [bookworm] - git <no-dsa> (Will be fixed in point release)
NOTE: https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
NOTE: Merge commit: https://github.com/git/git/commit/d61cfed2c23705fbeb9c0d08f59e75ee08738950 (v2.43.7)
CVE-2025-46334 (Git GUI allows you to use the Git source control management tools via ...)
@@ -11381,6 +11387,7 @@ CVE-2025-46334 (Git GUI allows you to use the Git source control management tool
NOTE: Merge commit: https://github.com/git/git/commit/d61cfed2c23705fbeb9c0d08f59e75ee08738950 (v2.43.7)
CVE-2025-27614 (Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Gi ...)
- git 1:2.50.1-0.1 (bug #1108983)
+ [trixie] - git <no-dsa> (Will be fixed in point release)
[bookworm] - git <not-affected> (Vulnerable code not present)
[bullseye] - git <not-affected> (Vulnerable code not present)
NOTE: https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
@@ -11389,6 +11396,8 @@ CVE-2025-27614 (Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0
NOTE: Fixed by: https://github.com/git/git/commit/8e3070aa5e331be45d4d03e3be41f84494fce129 (v2.43.7)
CVE-2025-27613 (Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when ...)
- git 1:2.50.1-0.1 (bug #1108983)
+ [trixie] - git <no-dsa> (Will be fixed in point release)
+ [bookworm] - git <no-dsa> (Will be fixed in point release)
NOTE: https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
NOTE: Merge commit: https://github.com/git/git/commit/d61cfed2c23705fbeb9c0d08f59e75ee08738950 (v2.43.7)
CVE-2024-36357 (A transient execution vulnerability in some AMD processors may allow a ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a588ca1274452edf58890aaefc3e7fe57755e9ab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a588ca1274452edf58890aaefc3e7fe57755e9ab
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250815/ad6c0fc0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list