Debian Security Update DSA-3984 git - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,788
Reaction score
74
Credits
-1,257
joernchen discovered that the git-cvsserver subcommand of Git, a distributed version control system, suffers from a shell command injection vulnerability due to unsafe use of the Perl backtick operator. The git-cvsserver subcommand is reachable from the git-shell subcommand even if CVS support has not been configured (however, the git-cvs package needs to be installed).

Continue reading...
 


Follow Linux.org

Members online


Top