Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:0054-1

Опубликовано: 23 мар. 2019
Источник: suse-cvrf

Описание

Security update for gitolite

This update for gitolite fixes the following security issue:

  • CVE-2018-20683: The rsync command line was not handled correctly, allow malicious rsync options (boo#1121570)

The version update to 3.6.11 also contains a number of upstream bug fixes.

Список пакетов

SUSE Package Hub 15
gitolite-3.6.11-bp150.3.6.1
openSUSE Leap 15.0
gitolite-3.6.11-bp150.3.6.1

Описание

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.


Затронутые продукты
SUSE Package Hub 15:gitolite-3.6.11-bp150.3.6.1
openSUSE Leap 15.0:gitolite-3.6.11-bp150.3.6.1

Ссылки