Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-2561

Опубликовано: 08 дек. 2015
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2015-2561: git security update (MODERATE)

[1.8.3.1-6]

  • fix arbitrary code execution via crafted URLs Resolves: #1274737

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

emacs-git

1.8.3.1-6.el7

emacs-git-el

1.8.3.1-6.el7

git

1.8.3.1-6.el7

git-all

1.8.3.1-6.el7

git-bzr

1.8.3.1-6.el7

git-cvs

1.8.3.1-6.el7

git-daemon

1.8.3.1-6.el7

git-email

1.8.3.1-6.el7

git-gui

1.8.3.1-6.el7

git-hg

1.8.3.1-6.el7

git-p4

1.8.3.1-6.el7

git-svn

1.8.3.1-6.el7

gitk

1.8.3.1-6.el7

gitweb

1.8.3.1-6.el7

perl-Git

1.8.3.1-6.el7

perl-Git-SVN

1.8.3.1-6.el7

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

redhat
почти 10 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

CVSS3: 9.8
nvd
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

CVSS3: 9.8
debian
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper program ...

suse-cvrf
больше 9 лет назад

Recommended update for git