Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 18.04 LTS: USN-5871-2 Critical: Git Regression Fix

ubuntu
Calendar Grey March 2, 2023
Scroller Ubuntu
USN-5892-1 resolves a vulnerability in OpenSSL for Ubuntu 20.04 LTS to improve safety and correct errors.
USN-5871-1 caused a regression.

Summary

USN-5871-1 caused a regression.

Software Description:

- git: fast, scalable, distributed revision control system

Details:

USN-5871-1 fixed vulnerabilities in Git. A backport fixing

part of the vulnerability in CVE-2023-22490 was required.

This update fix this for Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that Git incorrectly handled certain repositories.

An attacker could use this issue to make Git uses its local

clone optimization even when using a non-local transport.

(CVE-2023-22490)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  git                             1:2.17.1-1ubuntu0.17

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5871-2

https://ubuntu.com/security/notices/USN-5871-1

CVE-2023-22490, https://bugs.launchpad.net/ubuntu/+source/git/+bug/2008277

Severity
critical
Lowest
Low
Medium
High
Critical

March 02, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.