Описание
Security update for gitolite
This update for gitolite fixes the following security issue:
- CVE-2018-20683: The rsync command line was not handled correctly, allow malicious rsync options (boo#1121570)
The version update to 3.6.11 also contains a number of upstream bug fixes.
Список пакетов
SUSE Package Hub 15
gitolite-3.6.11-bp150.3.6.1
openSUSE Leap 15.0
gitolite-3.6.11-bp150.3.6.1
Ссылки
- E-Mail link for openSUSE-SU-2019:0054-1
- SUSE Security Ratings
- SUSE Bug 1121570
- SUSE CVE CVE-2018-20683 page
Описание
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.
Затронутые продукты
SUSE Package Hub 15:gitolite-3.6.11-bp150.3.6.1
openSUSE Leap 15.0:gitolite-3.6.11-bp150.3.6.1
Ссылки
- CVE-2018-20683
- SUSE Bug 1121570