New git-core packages has been released for Debian GNU/Linux to fix a security issue

[SECURITY] [DSA-2114-1] New git-core packages fix regression
Debian Security Advisory DSA-2114-1 Stefan Fritsch
September 26, 2010
Package : git-core
Vulnerability : buffer overflow
Problem type : local
Debian-specific: no
CVE Id(s) : CVE-2010-2542
Debian bug : 595728 590026

The Debian stable point release 5.0.6 included updated packages of
the Git revision control system in order to fix a security issue.
Unfortunately, the update introduced a regression which could make
it impossible to clone or create git repositories. This upgrade
fixes this regression, which is tracked as Debian bug #595728.

The original security issue allowed an attacker to execute arbitrary
code if he could trick a local user to execute a git command in a
crafted working directory (CVE-2010-2542).

For the stable distribution (lenny), this problem has been fixed in

The packages for the hppa architecture are not included in this
advisory. However, the hppa architecture is not known to be affected
by the regression.

For the testing distribution (squeeze) and the unstable distribution
(sid), the security issue has been fixed in version 1.7.1-1.1. These
distributions were not affected by the regression.

We recommend that you upgrade your git-core packages.

Upgrade instructions
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 5.0 (stable) alias lenny
Stable updates are available for alpha, amd64, arm, armel, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

These files will probably be moved into the stable distribution on
its next update.

