libgit2 0.28.4+dfsg.1-2ubuntu0.1 source package in Ubuntu

Changelog

libgit2 (0.28.4+dfsg.1-2ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: Improper Verification of Cryptographic Signature
    - debian/patches/CVE-2023-22742.patch: perform host key checking
      by default when using ssh.
    - CVE-2023-22742
  * SECURITY UPDATE: use-after-free
    - debian/patches/CVE-2024-24577.patch: correct index check in
      has_dir_name function used by git_index_add.
    - CVE-2024-24577

 -- Fabian Toepfer <email address hidden>  Wed, 28 Feb 2024 08:18:43 +0100

Upload details

Uploaded by:
Fabian Toepfer
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates universe libs
Focal security universe libs

Downloads

File Size SHA-256 Checksum
libgit2_0.28.4+dfsg.1.orig.tar.xz 2.7 MiB 758517d1ff5124e732e999e2e50a501cb0d3c8bdcf64d1cec404ced6235c0bb7
libgit2_0.28.4+dfsg.1-2ubuntu0.1.debian.tar.xz 18.6 KiB 8a3d388a52655ac0eb1437097b9cac150bc5052ac4fa44d98bb6d4d21c2e773d
libgit2_0.28.4+dfsg.1-2ubuntu0.1.dsc 2.3 KiB 259c89491dbd17407b738316447c7afb0b7858478d39db3b194c92c40fad47a4

View changes file

Binary packages built by this source

libgit2-28: low-level Git library

 libgit2 is a portable, pure C implementation of the Git
 distributed version control system core methods provided as a
 re-entrant link-able library with a solid API.

libgit2-28-dbgsym: debug symbols for libgit2-28
libgit2-dev: low-level Git library (development files)

 libgit2 is a portable, pure C implementation of the Git
 distributed version control system core methods provided as a
 re-entrant link-able library with a solid API.
 .
 This package contains the development files for libgit2.