Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 6 MGASA-2018-0395 Critical: Git Code Execution Threat

mageia
Calendar Grey October 14, 2018
Dist Mageia Esm H88
MGASA-2018-0395 - Updated git packages fix security vulnerability Publication date: 14 Oct 2018 URL:
joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .g...

Summary

joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .gitmodules file in a project cloned with --recurse-submodules (CVE-2018-17456).

References

- https://bugs.mageia.org/show_bug.cgi?id=23642

- https://www.cve.org/CVERecord?id=CVE-2018-17456

Resolution

SRPMS

- 6/core/git-2.13.7-1.2.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0395.html
Type: security
CVE: CVE-2018-17456

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here