Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian DSA-3984-1: Git Shell Injection Risk in Git-CVSServer

debian
Calendar Grey September 26, 2017
Debian Logo
Enhance your git installations to mitigate a shell command injection vulnerability identified in git-cvsserver by joernchen.
joernchen discovered that the git-cvsserver subcommand of Git, a distributed version control system, suffers from a shell command injection vulnerability due to unsafe use of the P...

Summary

joernchen discovered that the git-cvsserver subcommand of Git, a
distributed version control system, suffers from a shell command
injection vulnerability due to unsafe use of the Perl backtick
operator. The git-cvsserver subcommand is reachable from the
git-shell subcommand even if CVS support has not been configured
(however, the git-cvs package needs to be installed).

In addition to fixing the actual bug, this update removes the
cvsserver subcommand from git-shell by default. Refer to the updated
documentation for instructions how to reenable in case this CVS
functionality is still needed.

For the oldstable distribution (jessie), this problem has been fixed
in version 1:2.1.4-2.1+deb8u5.

For the stable distribution (stretch), this problem has been fixed in
version 1:2.11.0-3+deb9u2.

For the unstable distribution (sid), this problem has been fixed in
version 1:2.14.2-1.

We recommend that you upgrade your git packages.

Further information about Debian Security Advisories, how to apply
these updates...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: git

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here