Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 10 DLA-3145-1 Critical: Git Remote Code Execution Threat

debian lts
Calendar Grey October 10, 2022
Dist Debian Esm H88
Uncover essential patches for Git weaknesses through the Debian LTS DLA-3145-1 security release to maintain system stability.
Several security vulnerabilities have been discovered in Git, a fast, scalable, distributed revision control system, which may affect multi-user systems

Summary

A specially crafted repository that contains symbolic links as well as
files using a clean/smudge filter such as Git LFS, may cause just-checked
out script to be executed while cloning onto a case-insensitive file system
such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and
macOS).

CVE-2021-40330

git_connect_git in connect.c allows a repository path to contain a newline
character, which may result in unexpected cross-protocol requests, as
demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1
substring.


For Debian 10 buster, these problems have been fixed in version
1:2.20.1-2+deb10u4.

We recommend that you upgrade your git packages.

For the detailed security status of git please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/git

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: git
Version: 1:2.20.1-2+deb10u4
CVE ID: CVE-2021-21300 CVE-2021-40330
Debian Bug: 985120

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here