git: arbitrary code execution when recursively cloning a malicious repository (CVE-2018-11235) SL7 x86_64 git-1.8.3.1-14.el7_5.x86_64.rpm git-daemon-1.8.3.1-14.el7_5.x86_64.rpm git-debuginfo-1.8.3.1-14.el7_5.x86_64.rpm git-svn-1.8.3.1-14.el7_5.x86_64.rpm noarch emacs-git-1.8.3.1-14.el7_5.noarch.rpm emacs-git-el-1.8.3.1-14.el7_5.noarch.rpm git-all-1.8.3.1-14.el7 [More...]. Synopsis: Important: git security update Advisory ID: SLSA-2018:1957-1 Issue Date: 2018-06-20 CVE Numbers: CVE-2018-11235 -- Security Fix(es): * git: arbitrary code execution when recursively cloning a malicious repository (CVE-2018-11235) -- SL7 x86_64 git-1.8.3.1-14.el7_5.x86_64.rpm git-daemon-1.8.3.1-14.el7_5.x86_64.rpm git-debuginfo-1.8.3.1-14.el7_5.x86_64.rpm git-svn-1.8.3.1-14.el7_5.x86_64.rpm noarch emacs-git-1.8.3.1-14.el7_5.noarch.rpm emacs-git-el-1.8.3.1-14.el7_5.noarch.rpm git-all-1.8.3.1-14.el7_5.noarch.rpm git-bzr-1.8.3.1-14.el7_5.noarch.rpm git-cvs-1.8.3.1-14.el7_5.noarch.rpm git-email-1.8.3.1-14.el7_5.noarch.rpm git-gui-1.8.3.1-14.el7_5.noarch.rpm git-hg-1.8.3.1-14.el7_5.noarch.rpm git-p4-1.8.3.1-14.el7_5.noarch.rpm gitk-1.8.3.1-14.el7_5.noarch.rpm gitweb-1.8.3.1-14.el7_5.noarch.rpm perl-Git-1.8.3.1-14.el7_5.noarch.rpm perl-Git-SVN-1.8.3.1-14.el7_5.noarch.rpm - Scientific Linux Development Team . Critical git security patch for SL7 mitigating potential arbitrary code execution vulnerabilities when cloning repositories.. git update, security patch, SL7 security, malicious repository. . Severity: Important. LinuxSecurity.com Team
This update avoids a malicious repository writing to files outside the local storage root.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-6a2709f065 2017-01-16 16:00:02.271009 -------------------------------------------------------------------------------- Name : SimGear Product : Fedora 25 Version : 2016.3.1 Release : 3.fc25 URL : Summary : Simulation library components Description : SimGear is a set of open-source libraries designed to be used as building blocks for quickly assembling 3d simulations, games, and visualization applications. -------------------------------------------------------------------------------- Update Information: This update avoids a malicious repository writing to files outside the local storage root. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade SimGear' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.