[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4581-1 git -- git

ID: oval:org.secpod.oval:def:69922Date: (C)2021-03-07   (M)2024-01-02
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in git, a fast, scalable, distributed revision control system. CVE-2019-1348 It was reported that the --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=..., allowing to overwrite arbitrary paths. CVE-2019-1387 It was discovered that submodule names are not validated strictly enough, allowing very targeted attacks via remote code execution when performing recursive clones. CVE-2019-19604 Joern Schneeweisz reported a vulnerability, where a recursive clone followed by a submodule update could execute code contained within the repository without the user explicitly having asked for that. It is now disallowed for `.gitmodules` to have entries that set `submodule.<name>.update=!command`. In addition this update addresses a number of security issues which are only an issue if git is operating on an NTFS filesystem .

Platform:
Linux Mint 4
Product:
git
Reference:
DSA-4581-1
CVE-2019-1348
CVE-2019-1349
CVE-2019-1352
CVE-2019-1353
CVE-2019-1387
CVE-2019-19604
CVE    6
CVE-2019-1348
CVE-2019-1349
CVE-2019-1353
CVE-2019-1387
...
CPE    2
cpe:/o:linux_mint:linux_mint:4
cpe:/a:git:git

© SecPod Technologies