Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A specially crafted URL in can potentially cause cgit to excessively use CPU and network resources, resulting in a Denial-of-Service. This update resolves that issue . MGASA-2019-0203 - Updated cgit packages fix security vulnerability Publication date: 02 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0203.html Type: security Affected Mageia releases: 6 A specially crafted URL in can potentially cause cgit to excessively use CPU and network resources, resulting in a Denial-of-Service. This update resolves that issue References: - https://bugs.mageia.org/show_bug.cgi?id=24843 SRPMS: - 6/core/cgit-0.12-3.2.mga6 . Critical update for Mgasa-2019-0203 resolves cgit DoS issue affecting Mageia 6 systems.. specially, crafted, potentially, cause, excessively, network, resources. . Severity: Critical. LinuxSecurity.com Team
Fix directory traversal vulnerability References: https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html https://git.zx2c4.com/cgit/commit/?id=53efaf30b. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a5a7f83e1b 2018-08-14 21:06:35.949884 --------------------------------------------------------------------------------Name : cgit Product : Fedora 28 Version : 1.1 Release : 11.fc28 URL : https://git.zx2c4.com/cgit/ Summary : A fast web interface for git Description : Cgit is a fast web interface for git. It uses caching to increase performance. --------------------------------------------------------------------------------Update Information: Fix directory traversal vulnerability References: https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html https://git.zx2c4.com/cgit/commit/?id=53efaf30b --------------------------------------------------------------------------------ChangeLog: * Fri Aug 3 2018 Todd Zullinger - 1.1-11 - Fix directory traversal vulnerability --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a5a7f83e1b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fix directory traversal vulnerability References: https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html https://git.zx2c4.com/cgit/commit/?id=53efaf30b. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a407b85547 2018-08-14 20:15:54.627754 --------------------------------------------------------------------------------Name : cgit Product : Fedora 27 Version : 1.1 Release : 11.fc27 URL : https://git.zx2c4.com/cgit/ Summary : A fast web interface for git Description : Cgit is a fast web interface for git. It uses caching to increase performance. --------------------------------------------------------------------------------Update Information: Fix directory traversal vulnerability References: https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html https://git.zx2c4.com/cgit/commit/?id=53efaf30b --------------------------------------------------------------------------------ChangeLog: * Fri Aug 3 2018 Todd Zullinger - 1.1-11 - Fix directory traversal vulnerability * Sun Feb 18 2018 Todd Zullinger - 1.1-10 - Use https for source URLs - Remove el5 conditionals - Use cgit.conf and config.mak for cgit/git build options - Drop obsolete %{buildroot} cleanup - Add gcc and make BuildRequires * Wed Feb 7 2018 Fedora Release Engineering - 1.1-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a407b85547' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for cgit ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2313-1 Rating: moderate References: #1103799 Cross-References: CVE-2018-14912 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cgit to version 1.2.1 fixes the following issues: The following security vulnerability was addressed: - CVE-2018-14912: Fixed a directory traversal vulnerability, when enable-http-clone=1 is not turned off (boo#1103799) The following other changes were made: - Update to upstream release 1.2.1: - syntax-highlighting: replace invalid unicode with '?' - ui-repolist: properly sort by age - ui-patch: fix crash when using path limit - Update bundled git to 2.11.1 - Update to upstream release 1.0: * Add repo.homepage/gitweb.homepage setting and homepage tab. * Show reverse paths in title bar so that browser tab shows filename. * Allow redirects even when caching is turned on. * More gracefully deal with unparsable commits. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-864=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): cgit-1.2.1-13.3.1 cgit-debuginfo-1.2.1-13.3.1 cgit-debugsource-1.2.1-13.3.1 References: https://www.suse.com/security/cve/CVE-2018-14912.html https://bugzilla.suse.com/1103799 -- . A fresh update for openSUSE addresses a vulnerability linked to directory traversal in cgit. Discover more about the recentadvancements in security protocols.. openSUSE Security, cgit Update, Directory Traversal Fix, Package Patching, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for cgit ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2308-1 Rating: moderate References: #1103799 Cross-References: CVE-2018-14912 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cgit fixes the following issues: The following security vulnerability was addressed: - CVE-2018-14912: Fixed a directory traversal vulnerability, when enable-http-clone=1 is not turned off (boo#1103799) The following other changes were made: - Update to upstream release 1.2.1 * syntax-highlighting: replace invalid unicode with '?' * ui-repolist: properly sort by age * ui-patch: fix crash when using path limit Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-863=1 Package List: - openSUSE Leap 15.0 (x86_64): cgit-1.2.1-lp150.2.3.1 cgit-debuginfo-1.2.1-lp150.2.3.1 cgit-debugsource-1.2.1-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-14912.html https://bugzilla.suse.com/1103799 -- . Patch resolves significant vulnerability in openSUSE cgit, swiftly managing directory traversal threats effectively.. openSUSE Security Update,cgit fixes,directory traversal issues. . LinuxSecurity.com Team
It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 "Jessie", this issue has been fixed in cgit version . Package : cgit Version : 0.10.2.git2.0.1-3+deb8u2 CVE ID : CVE-2018-14912 Debian Bug : #905382 It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 "Jessie", this issue has been fixed in cgit version 0.10.2.git2.0.1-3+deb8u2. We recommend that you upgrade your cgit packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
The package cgit before version 1.2.1-1 is vulnerable to directory traversal. . Arch Linux Security Advisory ASA-201808-2 ======================================== Severity: High Date : 2018-08-03 CVE-ID : CVE-2018-14912 Package : cgit Type : directory traversal Remote : Yes Link : https://security.archlinux.org/AVG-745 Summary ====== The package cgit before version 1.2.1-1 is vulnerable to directory traversal. Resolution ========= Upgrade to 1.2.1-1. # pacman -Syu "cgit> =1.2.1-1" The problem has been fixed upstream in version 1.2.1. Workaround ========= Turn off enable-http-clone=1 Description ========== cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. Impact ===== A remote attacker is able to read arbitrary files from the cgit server. References ========= https://bugs.chromium.org/p/project-zero/issues/detail?id=1627 https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html https://git.zx2c4.com/cgit/commit/?id=53efaf30b50f095cad8c160488c74bba3e3b2680 https://security.archlinux.org/CVE-2018-14912 . Arch Linux Security Notice ASA-202309-1 tackles a critical vulnerability in the cgit software, focusing on an elevated risk of directory traversal exploits.. Arch Linux,cgit,directory traversal,security advisory,package fix. . LinuxSecurity.com Team
Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when 'enable-http-clone=1' (default) is not turned off. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4263-1
Get the latest Linux and open source security news straight to your inbox.