Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Fedora 24: Security Update for Git Shell Remote Access Issue

fedora
Calendar Grey May 28, 2017
Dist Fedora Esm H88
A patch has been released to address a vulnerability in git-shell that allowed unauthorized remote access and interaction with pager functionality on Fedora 24.
An issue in `git-shell` could allow remote users to run an interactive pager

Summary

Git is a fast, scalable, distributed revision control system with an

unusually rich command set that provides both high-level operations

and full access to internals.

The git rpm installs common set of tools which are usually using with

small amount of dependencies. To install all git packages, including

tools for integrating with other SCMs, install the git-all meta-package.

An issue in `git-shell` could allow remote users to run an interactive pager.

From the [update announcement](https://public-inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): ... fix a

recently disclosed problem with "git shell", which may allow a user who

comes over SSH to run an interactive pager by causing it to spawn "git

upload-pack --help" (CVE-2017-8386). The announcement also notes: If

you are not running a server, or if your server has not been explicitly

configured to use git-shell as a login shell, you are not affected.

Also note that sites running "git shell" behind gitolite are NOT vulnerable.

Further details can be found in the commit message which fixed the issue

([3ec804490]().

su -c 'dnf upgrade git' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 24
Version: 2.7.5
Release: 1.fc24
Summary: Fast Version Control System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here