Joined: 12 May 2004
|Posted: Mon Mar 09, 2009 6:26 pm Post subject: [ GLSA 200903-15 ] git: Multiple vulnerabilties
|Gentoo Linux Security Advisory
Title: git: Multiple vulnerabilties (GLSA 200903-15)
Date: March 09, 2009
Multiple vulnerabilities in gitweb allow for remote execution of arbitrary
GIT - the stupid content tracker, the revision control system used by
the Linux kernel team.
Vulnerable: < 220.127.116.11
Unaffected: >= 18.104.22.168
Architectures: All supported architectures
Multiple vulnerabilities have been reported in gitweb that is part of
the git package:
Shell metacharacters related to git_search are not properly sanitized
Shell metacharacters related to git_snapshot and git_object are not
properly sanitized (CVE-2008-5517).
The diff.external configuration variable as set in a repository can be
executed by gitweb (CVE-2008-5916).
A remote unauthenticated attacker can execute arbitrary commands via
shell metacharacters in a query, remote attackers with write access to
a git repository configuration can execute arbitrary commands with the
privileges of the user running gitweb by modifying the diff.external
configuration variable in the repository and sending a crafted query to
There is no known workaround at this time.
All git users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-util/git-22.214.171.124"
Last edited by GLSA on Mon Aug 18, 2014 4:28 am; edited 2 times in total