Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-4581-1 Critical: Git Security Fixes for Multiple Threats

debian
Calendar Grey December 10, 2019
Debian Logo
Multiple vulnerabilities pertaining to Git have been identified, raising concerns over possible unauthorized remote code execution risks within Debian systems.
Several vulnerabilities have been discovered in git, a fast, scalable, distributed revision control system

Summary

CVE-2019-1348

It was reported that the --export-marks option of git fast-import is
exposed also via the in-stream command feature export-marks=...,
allowing to overwrite arbitrary paths.

CVE-2019-1387

It was discovered that submodule names are not validated strictly
enough, allowing very targeted attacks via remote code execution
when performing recursive clones.

CVE-2019-19604

Joern Schneeweisz reported a vulnerability, where a recursive clone
followed by a submodule update could execute code contained within
the repository without the user explicitly having asked for that. It
is now disallowed for `.gitmodules` to have entries that set
`submodule..update=!command`.

In addition this update addresses a number of security issues which are
only an issue if git is operating on an NTFS filesystem (CVE-2019-1349,
CVE-2019-1352 and CVE-2019-1353).

For the oldstable distribution (stretch), these problems have been fixed
in version 1:2.11.0-3+deb9u5.

For the stable ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: git
CVE ID: CVE-2019-1348 CVE-2019-1349 CVE-2019-1352 CVE-2019-1353

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here