MGASA-2017-0266

Source
https://advisories.mageia.org/MGASA-2017-0266.html
Import Source
https://advisories.mageia.org/MGASA-2017-0266.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0266
Related
Published
2017-08-13T22:19:29Z
Modified
2017-08-13T21:22:01Z
Summary
Updated git packages fix security vulnerability
Details

Joern Schneeweisz discovered that git, a distributed revision control system, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command, for instance via git submodules (CVE-2017-1000117).

References
Credits

Affected packages

Mageia:6 / git

Package

Name
git
Purl
pkg:rpm/mageia/git?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.13.5-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / git

Package

Name
git
Purl
pkg:rpm/mageia/git?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-1.mga5

Ecosystem specific

{
    "section": "core"
}