GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Mar 09, 2009 6:26 pm Post subject: [ GLSA 200903-15 ] git: Multiple vulnerabilties |
|
|
Gentoo Linux Security Advisory
Title: git: Multiple vulnerabilties (GLSA 200903-15)
Severity: high
Exploitable: remote
Date: March 09, 2009
Bug(s): #251343
ID: 200903-15
Synopsis
Multiple vulnerabilities in gitweb allow for remote execution of arbitrary
commands.
Background
GIT - the stupid content tracker, the revision control system used by
the Linux kernel team.
Affected Packages
Package: dev-util/git
Vulnerable: < 1.6.0.6
Unaffected: >= 1.6.0.6
Architectures: All supported architectures
Description
Multiple vulnerabilities have been reported in gitweb that is part of
the git package:
-
Shell metacharacters related to git_search are not properly sanitized
(CVE-2008-5516).
-
Shell metacharacters related to git_snapshot and git_object are not
properly sanitized (CVE-2008-5517).
-
The diff.external configuration variable as set in a repository can be
executed by gitweb (CVE-2008-5916).
Impact
A remote unauthenticated attacker can execute arbitrary commands via
shell metacharacters in a query, remote attackers with write access to
a git repository configuration can execute arbitrary commands with the
privileges of the user running gitweb by modifying the diff.external
configuration variable in the repository and sending a crafted query to
gitweb.
Workaround
There is no known workaround at this time.
Resolution
All git users should upgrade to the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-util/git-1.6.0.6" |
References
CVE-2008-5516
CVE-2008-5517
CVE-2008-5916
Last edited by GLSA on Mon Aug 18, 2014 4:28 am; edited 2 times in total |
|