Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian: DSA-5357-1 Critical Update for Git Exfiltration Risk

debian
Calendar Grey February 23, 2023
Debian Logo
Ubuntu Security Notice USN-5142-1 pertains to severe vulnerabilities in OpenSSH, notably risk of unauthorized access. Immediate upgrade advised.
Brief introduction CVE-2023-22490

Summary

CVE-2023-22490

yvvdwf found a data exfiltration vulnerbility while performing local
clone from malicious repository even using a non-local transport.

CVE-2023-23946

Joern Schneeweisz found a path traversal vulnerbility in git-apply
that a path outside the working tree can be overwritten as the acting
user.

For the stable distribution (bullseye), these problems have been fixed in
version 1:2.30.2-1+deb11u2.

We recommend that you upgrade your git packages.

For the detailed security status of git please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/git

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: git
CVE ID: CVE-2023-22490 CVE-2023-23946

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here