summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/python-mapnik
diff options
context:
space:
mode:
authorThomas Gerbet <thomas@gerbet.me>2025-01-14 19:17:04 +0100
committerThomas Gerbet <thomas@gerbet.me>2025-01-14 19:17:04 +0100
commit7e92703f04b1096df66822ea227d8ffeeca3013d (patch)
treebf8714315573e37a552af124fd17f5d657c56eb0 /pkgs/development/python-modules/python-mapnik
parent07cfc4d3a1ac5a9e3e7922eb73b7ad9410da84b5 (diff)
git: 2.47.1 -> 2.47.2
Fixes CVE-2024-50349 and CVE-2024-52006 https://raw.githubusercontent.com/git/git/v2.47.2/Documentation/RelNotes/2.47.2.txt ``` - CVE-2024-50349: Printing unsanitized URLs when asking for credentials makes the user susceptible to crafted URLs (e.g. in recursive clones). These URLs can mislead the user into typing in passwords for trusted sites that would then be sent to untrusted sites instead. A potential scenario of how this can be exploited is a recursive clone where one of the submodules prompts for a password, pretending to ask for a different host than the password will be sent to. - CVE-2024-52006: Git may pass on Carriage Returns via the credential protocol to credential helpers which use line-reading functions that interpret Carriage Returns as line endings, even though this is not what was intended (but Git’s documentation did not clarify that "newline" meant "Line Feed character"). This affected the popular .NET-based Git Credential Manager, which has been updated accordingly in coordination with the Git project. ```
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik')
0 files changed, 0 insertions, 0 deletions