Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian Wheezy: DLA-1144-1 Moderate: git-annex Remote Command Execution

debian lts
Calendar Grey October 27, 2017
Dist Debian Esm H88
Enhance git-annex in response to operational error using ssh address containing hyphen in the hostname. Update to version 3.20120629+deb7u1 fixes the problems.
git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxy...

Summary

We recommend that you upgrade your git-annex packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: git-annex
Version: 3.20120629+deb7u1
CVE ID: CVE-2017-12976
Debian Bug: 873088

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here