Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2308-1

Опубликовано: 13 авг. 2018
Источник: suse-cvrf

Описание

Security update for cgit

This update for cgit fixes the following issues:

The following security vulnerability was addressed:

  • CVE-2018-14912: Fixed a directory traversal vulnerability, when enable-http-clone=1 is not turned off (boo#1103799)

The following other changes were made:

  • Update to upstream release 1.2.1
    • syntax-highlighting: replace invalid unicode with '?'
    • ui-repolist: properly sort by age
    • ui-patch: fix crash when using path limit

Список пакетов

openSUSE Leap 15.0
cgit-1.2.1-lp150.2.3.1

Описание

cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.


Затронутые продукты
openSUSE Leap 15.0:cgit-1.2.1-lp150.2.3.1

Ссылки