Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 10 Buster DLA-3282-1: Vulnerabilities in Git Code Execution

debian lts
Calendar Grey January 26, 2023
Dist Debian Esm H88
Recent findings indicate dual flaws in Git, posing risks of unauthorized code execution. It's essential to update Git packages to mitigate these security threats.
Two vulnerabilities were discovered in Git, a distributed revision control system

Summary

CVE-2022-23521

gitattributes are a mechanism to allow defining attributes for
paths. These attributes can be defined by adding a
`.gitattributes` file to the repository, which contains a set of
file patterns and the attributes that should be set for paths
matching this pattern. When parsing gitattributes, multiple
integer overflows can occur when there is a huge number of path
patterns, a huge number of attributes for a single pattern, or
when the declared attribute names are huge. These overflows can be
triggered via a crafted `.gitattributes` file that may be part of
the commit history. Git silently splits lines longer than 2KB when
parsing gitattributes from a file, but not when parsing them from
the index. Consequentially, the failure mode depends on whether
the file exists in the working tree, the index or both. This
integer overflow can result in arbitrary heap reads and writes,
which may result in remote code execution.

CVE-2022-41903

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: git
Version: 1:2.20.1-2+deb10u7
CVE ID: CVE-2022-23521 CVE-2022-41903
Debian Bug: 1029114

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here