Dulwich, when an SSH subprocess is used, allowed remote attackers to
execute arbitrary commands via an ssh URL with an initial dash character
in the hostname (CVE-2017-16228).
- https://bugs.mageia.org/show_bug.cgi?id=23346
- - https://www.cve.org/CVERecord?id=CVE-2017-16228
- 6/core/python-dulwich-0.12.0-1.2.mga6
Get the latest Linux and open source security news straight to your inbox.