Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 6: MGASA-2018-0434 Moderate: Gitolite Access Control Issue

mageia
Calendar Grey November 3, 2018
Dist Mageia Esm H88
Revised gitolite distributions fix permissions conflict permitting unauthorized Git repo visibility, announced 04 Nov 2018.
Updated gitolite package fixes security vulnerability: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repos...

Summary

Updated gitolite package fixes security vulnerability:
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access (CVE-2018-16976).

References

- https://bugs.mageia.org/show_bug.cgi?id=23680

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FW77TT3SZUDFVK3UYO6WNT7GFUHWXDUO/

- https://www.cve.org/CVERecord?id=CVE-2018-16976

Resolution

SRPMS

- 6/core/gitolite-3.6.10-1.mga6

Publication date: 03 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0434.html
Type: security
CVE: CVE-2018-16976

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here