Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228). References: . MGASA-2018-0445 - Updated python-dulwich packages fix security vulnerability Publication date: 11 Nov 2018 URL: https://advisories.mageia.org/MGASA-2018-0445.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-16228 Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228). References: - https://bugs.mageia.org/show_bug.cgi?id=23346 - - https://www.cve.org/CVERecord?id=CVE-2017-16228 SRPMS: - 6/core/python-dulwich-0.12.0-1.2.mga6 . Recent updates to python-dulwich packages address an issue with command execution in SSH configurations for Mageia operating systems.. Mageia Security Update, Dulwich Command Execution, Python-Dulwich Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.