Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Ubuntu: USN-5010-1 Low: git-annex Potential Vulnerability in Execution

debian
Calendar Grey October 30, 2017
Debian Logo
Familiarize yourself with Debian Security Announcement DSA-4010-1, which details a significant vulnerability in git-annex that could permit unauthorized command execution.
It was discovered that git-annex, a tool to manage files with git without checking their contents in, did not correctly handle maliciously constructed ssh:// URLs

Summary

For the oldstable distribution (jessie), this problem has been fixed
in version 5.20141125+deb8u1.

For the stable distribution (stretch), this problem has been fixed in
version 6.20170101-1+deb9u1.

We recommend that you upgrade your git-annex packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
low
Lowest
Low
Medium
High
Critical

Package: git-annex
CVE ID: CVE-2017-12976

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here