Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 25 Update: 2017-f4319b6dfc Moderate Interactive Shell Access

fedora
Calendar Grey May 15, 2017
Dist Fedora Esm H88
Fedora 25 has issued a Git update that resolves a vulnerability related to interactive shell access within git-shell, bolstering its security measures.
An issue in `git-shell` could allow remote users to run an interactive pager

Summary

Git is a fast, scalable, distributed revision control system with an

unusually rich command set that provides both high-level operations

and full access to internals.

The git rpm installs common set of tools which are usually using with

small amount of dependencies. To install all git packages, including

tools for integrating with other SCMs, install the git-all meta-package.

An issue in `git-shell` could allow remote users to run an interactive pager.

From the [update announcement](https://public-inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): ... fix a

recently disclosed problem with "git shell", which may allow a user who

comes over SSH to run an interactive pager by causing it to spawn "git

upload-pack --help" (CVE-2017-8386). The announcement also notes: If

you are not running a server, or if your server has not been explicitly

configured to use git-shell as a login shell, you are not affected.

Also note that sites running "git shell" behind gitolite are NOT vulnerable.

Further details can be found in the commit message which fixed the issue

([3ec804490]().

su -c 'dnf upgrade git' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 25
Version: 2.9.4
Release: 1.fc25
Summary: Fast Version Control System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here