git-lfs-3.4.1-4.el8_10

エラータID: AXSA:2025-9621:02

Release date: 
Monday, February 3, 2025 - 19:05
Subject: 
git-lfs-3.4.1-4.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):

* git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs (CVE-2024-53263)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. git-lfs-3.4.1-4.el8_10.src.rpm
    MD5: 800e5a1635e8ce059f9644704e56e6e9
    SHA-256: 1ed8f35625d6a84600e20e2f513f64a81f36df6ff4b6ba321e67773107e2542d
    Size: 3.38 MB

Asianux Server 8 for x86_64
  1. git-lfs-3.4.1-4.el8_10.x86_64.rpm
    MD5: 37a3ff287eee5630b0e35714fa37024e
    SHA-256: 12bed4e53359bc70e413bceac117e7105edc344451d57a975274d13ca9c9e3e7
    Size: 4.34 MB