Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out the host name for which the user is expected to provide a username and/or a password. At this stage, any URL-encoded parts have been decoded already, and are printed verbatim. This allows attackers to craft URLs that contain ANSI escape sequences that the terminal interpret to confuse users e.g. into providing passwords for trusted Git hosting sites when in fact they are then sent to untrusted sites that are under the attacker's control. This issue has been patch via commits 7725b81 and c903985 which are included in release versions v2.48.1, v2.47.2, v2.46.3, v2.45.3, v2.44.3, v2.43.6, v2.42.4, v2.41.3, and v2.40.4. Users are advised to upgrade. Users unable to upgrade should avoid cloning from untrusted URLs, especially recursive clones.
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.25.1-1ubuntu3.14"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.34.1-1ubuntu1.12"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.43.0-1ubuntu7.2"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.47.1-1ubuntu1"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.47.1-1ubuntu1"
        }
    ]
}{
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-arch",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-core",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm11"
        }
    ]
}{
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm4"
        }
    ]
}