Oracle Linux 6277 Published by

A git security update has been released for Oracle Linux 7.



ELSA-2020-2337 Important: Oracle Linux 7 git security update

Oracle Linux Security Advisory ELSA-2020-2337

http://linux.oracle.com/errata/ELSA-2020-2337.html

The following updated rpms for Oracle Linux 7 have been uploaded to the
Unbreakable Linux Network:

x86_64:
emacs-git-1.8.3.1-23.el7_8.noarch.rpm
emacs-git-el-1.8.3.1-23.el7_8.noarch.rpm
git-1.8.3.1-23.el7_8.x86_64.rpm
git-all-1.8.3.1-23.el7_8.noarch.rpm
git-bzr-1.8.3.1-23.el7_8.noarch.rpm
git-cvs-1.8.3.1-23.el7_8.noarch.rpm
git-daemon-1.8.3.1-23.el7_8.x86_64.rpm
git-email-1.8.3.1-23.el7_8.noarch.rpm
git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm
git-gui-1.8.3.1-23.el7_8.noarch.rpm
git-hg-1.8.3.1-23.el7_8.noarch.rpm
git-instaweb-1.8.3.1-23.el7_8.noarch.rpm
git-p4-1.8.3.1-23.el7_8.noarch.rpm
git-svn-1.8.3.1-23.el7_8.x86_64.rpm
gitk-1.8.3.1-23.el7_8.noarch.rpm
gitweb-1.8.3.1-23.el7_8.noarch.rpm
perl-Git-1.8.3.1-23.el7_8.noarch.rpm
perl-Git-SVN-1.8.3.1-23.el7_8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/git-1.8.3.1-23.el7_8.src.rpm


Description of changes:

[1.8.3.1-23]
- Prevent crafted URL containing new lines, empty host or lacks a scheme
to cause credential leak.
Resolves: CVE-2020-11008