Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora: 2019-b276ee69a8 Critical: Gitolite3 Security Patch Released

3.6.11: https://github.com/sitaramc/gitolite/commit/b49133dc5f49b12807165ed2503 07213c1ac0a53. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b276ee69a8 2019-01-19 02:25:20.762956 --------------------------------------------------------------------------------Name : gitolite3 Product : Fedora 29 Version : 3.6.11 Release : 1.fc29 URL : https://github.com/sitaramc/gitolite Summary : Highly flexible server for git directory version tracker Description : Gitolite allows a server to host many git repositories and provide access to many developers, without having to give them real userids on the server. The essential magic in doing this is ssh's pubkey access and the authorized keys file, and the inspiration was an older program called gitosis. Gitolite can restrict who can read from (clone/fetch) or write to (push) a repository. It can also restrict who can push to what branch or tag, which is very important in a corporate environment. Gitolite can be installed without requiring root permissions, and with no additional software than git itself and perl. It also has several other neat features described below and elsewhere in the doc/ directory. --------------------------------------------------------------------------------Update Information: 3.6.11: https://github.com/sitaramc/gitolite/commit/b49133dc5f49b12807165ed2503 07213c1ac0a53 --------------------------------------------------------------------------------ChangeLog: * Tue Jan 8 2019 Gwyn Ciesla - 1:3.6.11-1 - 3.6.11. * Thu Oct 4 2018 Gwyn Ciesla - 1:3.6.10-1 - 3.6.10. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b276ee69a8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Gitolite3 security patch for Fedora 29 introduces critical enhancements. Update immediately to safeguard your environments.. Fedora Security Update, Gitolite Security Issues, Software Vulnerabilities, Linux Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 19, 2019 Critical Fedora
202

openSUSE: 2019:0054-1 Moderate Update for Gitolite Security Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for gitolite ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0054-1 Rating: moderate References: #1121570 Cross-References: CVE-2018-20683 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gitolite fixes the following security issue: - CVE-2018-20683: The rsync command line was not handled correctly, allow malicious rsync options (boo#1121570) The version update to 3.6.11 also contains a number of upstream bug fixes. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-54=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-54=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-54=1 Package List: - openSUSE Leap 42.3 (noarch): gitolite-3.6.11-4.6.1 - openSUSE Leap 15.0 (noarch): gitolite-3.6.11-lp150.2.6.1 - openSUSE Backports SLE-15 (noarch): gitolite-3.6.11-bp150.3.6.1 References: https://www.suse.com/security/cve/CVE-2018-20683.html https://bugzilla.suse.com/1121570 -- . openSUSE Security Patch for gitolite addresses a moderate vulnerability linked to rsync command processing. Update is now accessible.. openSUSE Security Update, gitolite security patch, rsync command issue. . LinuxSecurity.com Team

Calendar 2 Jan 18, 2019 OpenSUSE
202

openSUSE: 2018:3035-1 Moderate: Gitolite Access Control Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for gitolite ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3035-1 Rating: moderate References: #1108272 Cross-References: CVE-2018-16976 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gitolite fixes the following issues: Gitolite was updated to 3.6.9: - CVE-2018-16976: prevent racy access to repos in process of migration to gitolite (boo#1108272) - 'info' learns new '-p' option to show only physical repos (as opposed to wild repos) The update to 3.6.8 contains: - fix bug when deleting *all* hooks for a repo - allow trailing slashes in repo names - make pre-receive hook driver bail on non-zero exit of a pre-receive hook - allow templates in gitolite.conf (new feature) - various optimiations The update to 3.6.7 contains: - allow repo-specific hooks to be organised into subdirectories, and allow the multi-hook driver to be placed in some other location of your choice - allow simple test code to be embedded within the gitolite.conf file; see contrib/utils/testconf for how. (This goes on the client side, not on the server) - allow syslog "facility" to be changed, from the default of 'local0' - allow syslog "facility" to be changed, from the default of replaced with a space separated list of members The update to 3.6.6 contains: - simple but important fix for a future perl deprecation (perl will be removing "." from @INC in 5.24) - 'perms' now requires a '-c' to activate batch mode (should not affect interactive use but check your scripts perhaps?) - gitolitesetup now accepts a '-m' option to supply a custom message (useful when it is used by a script) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1118=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1118=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2018-1118=1 Package List: - openSUSE Leap 42.3 (noarch): gitolite-3.6.9-4.3.1 - openSUSE Leap 15.0 (noarch): gitolite-3.6.9-lp150.2.3.1 - openSUSE Backports SLE-15 (noarch): gitolite-3.6.9-bp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2018-16976.html https://bugzilla.suse.com/1108272 -- . New gitolite version released for openSUSE to tackle security vulnerabilities with moderate risks. Key updates implemented.. openSUSE Update, GITolite Security, Access Control Issues. . LinuxSecurity.com Team

Calendar 2 Oct 05, 2018 OpenSUSE
89

OpenSUSE Leap 15 Update: 2018-bc072d7a2f Critical Gitolite3 Access Issue

3.6.9. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-dc060c6f2a 2018-09-21 07:41:02.267708 --------------------------------------------------------------------------------Name : gitolite3 Product : Fedora 28 Version : 3.6.9 Release : 1.fc28 URL : https://github.com/sitaramc/gitolite Summary : Highly flexible server for git directory version tracker Description : Gitolite allows a server to host many git repositories and provide access to many developers, without having to give them real userids on the server. The essential magic in doing this is ssh's pubkey access and the authorized keys file, and the inspiration was an older program called gitosis. Gitolite can restrict who can read from (clone/fetch) or write to (push) a repository. It can also restrict who can push to what branch or tag, which is very important in a corporate environment. Gitolite can be installed without requiring root permissions, and with no additional software than git itself and perl. It also has several other neat features described below and elsewhere in the doc/ directory. --------------------------------------------------------------------------------Update Information: 3.6.9 --------------------------------------------------------------------------------ChangeLog: * Tue Sep 11 2018 Gwyn Ciesla - 1:3.6.9-1 - Latest upstream. * Tue Jul 17 2018 Gwyn Ciesla - 1:3.6.8-1 - Latest upstream. * Fri Jul 13 2018 Fedora Release Engineering - 1:3.6.7-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Jun 27 2018 Jitka Plesnikova - 1:3.6.7-6 - Perl 5.28 rebuild * Tue Apr 24 2018 Pierre-Yves Chibon - 1:3.6.7-5 - Back upstream patch making gitolite respect the ALLOW_ORPHAN_GL_CONF configuration variabe - Include the compile-1 command upstream brought in Fedora in: https://github.com/sitaramc/gitolite/commit/afb8afa14a892895dc48664c6526351cb --------------------------------------------------------------------------------References: [ 1 ] Bug #1629930 - CVE-2018-16976 gitolite3: gitolite: Improper restriction of access to a Git repository while migration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1629930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-dc060c6f2a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important security patch for gitolite in Fedora 28 focusing on user permissions and safeguarding repository authenticity.. Gitolite Update,Fedora Security Alert,Repository Management Tool,Access Control Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 21, 2018 Critical Fedora
89

Fedora 29 Gitolite3 Security Advisory: Access Control Flaws Addressed

3.6.9. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-d0bac4ff3b 2018-09-21 05:19:39.112401 --------------------------------------------------------------------------------Name : gitolite3 Product : Fedora 29 Version : 3.6.9 Release : 1.fc29 URL : https://github.com/sitaramc/gitolite Summary : Highly flexible server for git directory version tracker Description : Gitolite allows a server to host many git repositories and provide access to many developers, without having to give them real userids on the server. The essential magic in doing this is ssh's pubkey access and the authorized keys file, and the inspiration was an older program called gitosis. Gitolite can restrict who can read from (clone/fetch) or write to (push) a repository. It can also restrict who can push to what branch or tag, which is very important in a corporate environment. Gitolite can be installed without requiring root permissions, and with no additional software than git itself and perl. It also has several other neat features described below and elsewhere in the doc/ directory. --------------------------------------------------------------------------------Update Information: 3.6.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1629930 - CVE-2018-16976 gitolite3: gitolite: Improper restriction of access to a Git repository while migration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1629930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-d0bac4ff3b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Stay updated on Fedora's latest gitolite3 update addressing vital security flaws while enhancing access controls, crucial for secure repository management and user access.. Gitolite Update, Fedora Security, Access Control Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 21, 2018 Important Fedora
87

Debian: DSA-2215-1 Moderate: Gitolite Directory Traversal Threat

Dylan Simon discovered that gitolite, a SSH-based gatekeeper for git repositories, is prone to directory traversal attacks when restricting admin defined commands (ADC). This allows an attacker to execute arbitrary commands with privileges of the gitolite server via crafted command names. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2215-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde April 9, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gitolite Vulnerability : directory traversal Problem type : remote Debian-specific: no CVE ID : none yet Dylan Simon discovered that gitolite, a SSH-based gatekeeper for git repositories, is prone to directory traversal attacks when restricting admin defined commands (ADC). This allows an attacker to execute arbitrary commands with privileges of the gitolite server via crafted command names. Please note that this only affects installations that have ADC enabled (not the Debian default). The oldstable distribution (lenny) is not affected by this problem, it does not include gitolite. For the stable distribution (squeeze), this problem has been fixed in version 1.5.4-2+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 1.5.7-2. For the unstable distribution (sid), this problem has been fixed in version 1.5.7-2. We recommend that you upgrade your gitolite packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance gitolite setup to address vulnerabilities related to directory traversal, preventing unauthorized command execution on the server..gitolite security, remote access threats, Debian advisory, directory traversal, git security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 09, 2011 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here