git-lfs-3.4.1-4.el9_5

エラータID: AXSA:2025-9577:01

Release date: 
Monday, January 27, 2025 - 10:48
Subject: 
git-lfs-3.4.1-4.el9_5
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):

* git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs (CVE-2024-53263)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. git-lfs-3.4.1-4.el9_5.src.rpm
    MD5: 36676a481f18d1e6eae1b67dcce8eb8e
    SHA-256: 187836b738e823a8ad2990201e57f43baef7e9b3fa746d6ae0b4566ed3d7741f
    Size: 3.34 MB

Asianux Server 9 for x86_64
  1. git-lfs-3.4.1-4.el9_5.x86_64.rpm
    MD5: 31a7626133f2ee6e810e3299cfa8af1e
    SHA-256: 6e32204e51f113a25549725f2e04c3c41dc0837b30d05c41d6756f9b7b547a2c
    Size: 4.29 MB