Joined: 12 May 2004
|Posted: Mon Mar 09, 2009 6:26 pm Post subject: [ GLSA 200903-15 ] git: Multiple vulnerabilties
|Gentoo Linux Security Advisory
Title: git: Multiple vulnerabilties (GLSA 200903-15)
Date: March 09, 2009
Multiple vulnerabilities in gitweb allow for remote execution of arbitrary commands.
GIT - the stupid content tracker, the revision control system used by the Linux kernel team.
Vulnerable: < 188.8.131.52
Unaffected: >= 184.108.40.206
Architectures: All supported architectures
Multiple vulnerabilities have been reported in gitweb that is part of the git package:
- Shell metacharacters related to git_search are not properly sanitized (CVE-2008-5516).
- Shell metacharacters related to git_snapshot and git_object are not properly sanitized (CVE-2008-5517).
- The diff.external configuration variable as set in a repository can be executed by gitweb (CVE-2008-5916).
A remote unauthenticated attacker can execute arbitrary commands via shell metacharacters in a query, remote attackers with write access to a git repository configuration can execute arbitrary commands with the privileges of the user running gitweb by modifying the diff.external configuration variable in the repository and sending a crafted query to gitweb.
There is no known workaround at this time.
All git users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-util/git-220.127.116.11"