Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 6 MGASA-2018-0445 High: Python-Dulwich SSH Threat

mageia
Calendar Grey November 11, 2018
Dist Mageia Esm H88
Recent updates to python-dulwich packages address an issue with command execution in SSH configurations for Mageia operating systems.
Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228)

Summary

Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228).

References

- https://bugs.mageia.org/show_bug.cgi?id=23346

- - https://www.cve.org/CVERecord?id=CVE-2017-16228

Resolution

SRPMS

- 6/core/python-dulwich-0.12.0-1.2.mga6

Publication date: 11 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0445.html
Type: security
CVE: CVE-2017-16228

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here