Re: CVE-2020-5260: Git: malicious URLs may cause Git to present stored credentials to the wrong server

Related Vulnerabilities: CVE-2020-5260  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Re: CVE-2020-5260: Git: malicious URLs may cause Git to present stored credentials to the wrong server

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Taylor Blau &lt;ttaylorr () github com&gt;

Date: Wed, 15 Apr 2020 13:31:43 -0600

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Hi all,

On Wed, Apr 15, 2020 at 08:59:44PM +0200, Solar Designer wrote:
Hi,

Taylor Blau brought this to the distros list a week ago (thanks!), but
unfortunately failed to follow the distros list policy (despite of being
specifically informed of that requirement by distros list members,
twice) to post the information to oss-security on the public disclosure
date/time.  So as list admin, after a delay of more than a day, I am
taking over and do this (being unhappy that I have to do it for others).

My sincerest apologies for not sending this to oss-security in the
appropriate time. We (the git-security) list had discussed that I would
do so, and clearly it had slipped my mind.

The remainder of Alexander's guidance is correct from our perspective.
I'll make sure to avoid this mishap in the future by remembering to
email this list more promptly. Thanks, and sorry again.

Quoting Taylor's original notification to distros:

[snip]

Thanks,
Taylor

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

CVE-2020-5260: Git: malicious URLs may cause Git to present stored credentials to the wrong server Solar Designer (Apr 15)

Re: CVE-2020-5260: Git: malicious URLs may cause Git to present stored credentials to the wrong server Taylor Blau (Apr 15)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->