Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 14.04 ESM USN-5810-4 Critical Threat: Git Code Execution Risks

ubuntu
Calendar Grey March 1, 2023
Scroller Ubuntu
Enhance your security framework by applying the recent patch for vulnerabilities in Git for Ubuntu 14.04 ESM. Ensure your environment is safeguarded with this critical notification.
Several security issues were fixed in Git.

Summary

Several security issues were fixed in Git.

Software Description:

- git: fast, scalable, distributed revision control system

Details:

USN-5810-1 fixed several vulnerabilities in Git. This update provides

the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

Markus Vervier and Eric Sesterhenn discovered that Git incorrectly handled certain

gitattributes. An attacker could possibly use this issue to cause a crash

or execute arbitrary code. (CVE-2022-23521)

Joern Schneeweisz discovered that Git incorrectly handled certain commands.

An attacker could possibly use this issue to cause a crash or execute

arbitrary code. (CVE-2022-41903)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  git                             1:1.9.1-1ubuntu0.10+esm1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5810-4

https://ubuntu.com/security/notices/USN-5810-1

CVE-2022-23521, CVE-2022-41903

Severity
critical
Lowest
Low
Medium
High
Critical

March 01, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.