Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20683

Опубликовано: 10 янв. 2019
Источник: debian

Описание

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitolite3fixed3.6.11-1package
gitolite3no-dsastretchpackage
gitolite3no-dsajessiepackage
gitoliteremovedpackage

Примечания

  • https://github.com/sitaramc/gitolite/commit/5df2b817255ee919991da6c310239e08c8fcc1ae

  • https://groups.google.com/forum/#!topic/gitolite-announce/6xbjjmpLePQ

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

CVSS3: 8.1
nvd
около 7 лет назад

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

suse-cvrf
почти 7 лет назад

Security update for gitolite

CVSS3: 8.1
github
больше 3 лет назад

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.