drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in git
Name: |
Ausführen beliebiger Kommandos in git |
|
ID: |
DSA-4212-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian jessie, Debian stretch |
|
Datum: |
Di, 29. Mai 2018, 23:37 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11235 |
|
Applikationen: |
Git |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-4212-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 29, 2018 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : git CVE ID : CVE-2018-11235
Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.
For the oldstable distribution (jessie), this problem has been fixed in version 1:2.1.4-2.1+deb8u6.
For the stable distribution (stretch), this problem has been fixed in version 1:2.11.0-3+deb9u3.
We recommend that you upgrade your git packages.
For the detailed security status of git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/git
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlsNulpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Q6vw//ZCBWhKxjVKMiUin8guKdxVBps/Rhj6jmth+QEerAOA+WWXMW3APqt6wX nD7aIfwwj5whR9CXfDl9PmH690jgfaz615eVv7UOHqAb+RAx0whl6wm0e0UcpyLA wCMfneD1O+Sw5qnC7167QMpiY8PjIHO9DXwEOeEovu3igB2RET0WQxsdvme5MN9H 8ydmMIYSHuHZrOBwiE8rcQMyg5EoSkMih3cSCMiR+uqyCySxOV1kwy+9hiAUiwm1 BeI11h4HPlwzDmu+fKS+1KNEWRu09j1uBVZ1H8U4r7X9kfllcUyMX0CMUlf9HEgS iz39zhn4DEBFiCCxgwvvAkChxez7YW1oBoIAnELZQnPNkewYx5bd36Rbi+UBy34I pMiqqIET1CkZ5flP/IFgCg2fRZ3gtu4heLZfL8rsvxkjzp8PomscrroHpRC2CF4I KWM1Z+qfy59Ix4pNgvHWoMHjUOQoYUWYwYUb+J7fTPdqr2nxksiQbY8ZwdBU46/T menxp6Pf25cj8ozc0G2GNR8saLSOy1b1b25AF8yiLqc3LjzlNna/9BMEFiC4xHMD NnoExq3a+8iDh48KyxnahUaEHL68c0qbNtlDKfD2P5lYTCMijCtm7IsyiC2F9qKP FOjc9FsZq/NkfkEYx6wy/jQEypgjKJqbxwhc5IKTaTAIIxIDY9M= =cpDE -----END PGP SIGNATURE-----
|
|
|
|