Bug 33931 - git-lfs new security issue CVE-2024-53263
Summary: git-lfs new security issue CVE-2024-53263
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-01-17 15:27 CET by Nicolas Salguero
Modified: 2025-01-30 19:37 CET (History)
3 users (show)

See Also:
Source RPM: git-lfs-3.2.0-1.mga9.src.rpm
CVE: CVE-2024-53263
Status comment:


Attachments

Description Nicolas Salguero 2025-01-17 15:27:11 CET
openSUSE has issued an advisory on January 16:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/U4RACGLXZEZGUX7BZLFN4GQOHFBHL6FO/
Nicolas Salguero 2025-01-17 15:27:43 CET

Status comment: (none) => Fixed upstream in 3.6.1
Source RPM: (none) => git-lfs-3.2.0-1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2024-53263

Comment 1 Lewis Smith 2025-01-26 19:51:36 CET
NicolasS is already doing this, so changing the assignment.

Assignee: bugsquad => nicolas.salguero

Comment 2 Nicolas Salguero 2025-01-28 17:14:27 CET
Debian has issued an advisory on January 24:
https://lists.debian.org/debian-security-announce/2025/msg00011.html
Comment 3 Nicolas Salguero 2025-01-29 10:11:41 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Git LFS permits exfiltration of credentials via crafted HTTP URLs. (CVE-2024-53263)

References:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/U4RACGLXZEZGUX7BZLFN4GQOHFBHL6FO/
https://lists.debian.org/debian-security-announce/2025/msg00011.html
========================

Updated packages in core/updates_testing:
========================
git-lfs-3.2.0-1.1.mga9
golang-github-git-lfs-3-devel-3.2.0-1.1.mga9

from SRPM:
git-lfs-3.2.0-1.1.mga9.src.rpm

Assignee: nicolas.salguero => qa-bugs
Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Status comment: Fixed upstream in 3.6.1 => (none)
Status: NEW => ASSIGNED

Comment 4 Herman Viaene 2025-01-29 15:00:39 CET
MGA9-64 Plasma Wayland on Compaq H000SB
Installation draws in some 376 git- and golang packages.
AFAICS is git and golang developer territory and there are no previous updates, so giving the OK on clean install.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

katnatek 2025-01-29 18:21:22 CET

CC: (none) => andrewsfarm
Keywords: (none) => advisory

Comment 5 Thomas Andrews 2025-01-29 20:44:02 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 6 Mageia Robot 2025-01-30 19:37:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0028.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.