Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Slackware: 2017-223-01 Critical: Git Command Injection Threat

slackware
Calendar Grey August 11, 2017
Dist Slackware Esm H88
Latest git versions made available for Slackware aimed at fixing significant security vulnerabilities and improving comprehensive system safeguarding.
New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/git-2.14.1-i586-1_slack14.2.txz: Upgraded. Fixes security issues: A "ssh://..." URL can result in a "ssh" command line with a hostname that begins with a dash "-", which would cause the "ssh" command to instead (mis)treat it as an option. This is now prevented by forbidding such a hostname (which should not impact any real-world usage). Similarly, when GIT_PROXY_COMMAND is configured, the command is run with host and port that are parsed out from "ssh://..." URL; a poorly written GIT_PROXY_COMMAND could be tricked into treating a string that begins with a dash "-" as an option. This is now prevented by forbidding such a hostname and port number (again, which should not impact any real-world usage). For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-1000117 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: eb09b59fc1bb219e829caa8fc3619bd6 git-2.14.1-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: 1a31cef1c6c5a81a09635d25ea3090ff git-2.14.1-x86_64-1_slack13.0.txz
Slackware 13.1 package: 77c2adf3715328fd28a075d19b636fc1 git-2.14.1-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: b382a2bde0bad0f83e13788c4e2dd9b2 git-2.14.1-x86_64-1_slack13.1.txz
Slackware 13.37 package: 7858189706b9da7a8822b43fcc57038e git-2.14.1-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: 951d45486e41bfca03a99b52dbe82f2c git-2.14.1-x86_64-1_slack13.37.txz
Slackware 14.0 package: e1d681ce44de2459fcd2e1f06b83fb7e git-2.14.1-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 6eb717a73dc54f4c5dcdad9710636a38 git-2.14.1-x86_64-1_slack14.0.txz
Slackware 14.1 package: 211e9d242f3044bc2f3920d978c148d1 git-2.14.1-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 4e0d3510b71bf1e5a0ede2b6f41e330e git-2.14.1-x86_64-1_slack14.1.txz
Slackware 14.2 package: f065edb1ef108a8cefe74292441ad77b git-2.14.1-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: c29b1e8d760661c0c1cb62cccb316f55 git-2.14.1-x86_64-1_slack14.2.txz
Slackware -current package: e7765505e32c34d6b23160dc207932af d/git-2.14.1-i586-1.txz
Slackware x86_64 -current package: 9659eaf46710b5514ca804f44b451910 d/git-2.14.1-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg git-2.14.1-i586-1_slack14.2.txz

Related News

Your message here