Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2023-0163 Critical: Git Configuration Injection & Execution Issue

mageia
Calendar Grey May 6, 2023
Dist Mageia Esm H88
Recent Git package updates in Mageia tackle significant security vulnerabilities concerning configuration tampering and arbitrary code execution.
By feeding specially crafted input to 'git apply --reject', a path outside the working tree can be overwritten with partially controlled contents corresponding to the rejected hunk...

Summary

By feeding specially crafted input to 'git apply --reject', a path outside the working tree can be overwritten with partially controlled contents corresponding to the rejected hunk(s) from the given patch. (CVE-2023-25652).
When Git is compiled with runtime prefix support and runs without translated messages, it still used the gettext machinery to display messages, which subsequently potentially looked for translated messages in unexpected places. This allowed for malicious placement of crafted messages (CVE-2023-25815).
When renaming or deleting a section from a configuration file, certain malicious configuration values may be misinterpreted as the beginning of a new configuration section, leading to arbitrary configuration injection (CVE-2023-29007).

References

- https://bugs.mageia.org/show_bug.cgi?id=31856

-

- https://lore.kernel.org/git/xmqqa5yv3n93.fsf@gitster.g/T/

- https://www.cve.org/CVERecord?id=CVE-2023-25652

- https://www.cve.org/CVERecord?id=CVE-2023-25815

- https://www.cve.org/CVERecord?id=CVE-2023-29007

Resolution

SRPMS

- 8/core/git-2.30.9-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0163.html
Type: security
CVE: CVE-2023-25652, CVE-2023-25815, CVE-2023-29007

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here