Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· System Builder Marathon, Q2 2013 and more
· Microsoft delivers biggest update to date to TypeScript
· Tiff/nss-pam-ldapd Updates for Debian
· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review
· Microsoft launches Surface RT discount for schools
· MacStadium to provide new Mac Pro hosting and colocation
· Netflix outside the USA - in Linux & with Tunlr

Upcoming News
· =?UTF-8?B?W0FmZmlsaWF0ZXMgTmV3c10gT0NaIFZlcnRleCAzLjIwIDI0MEdCIFNvbGlkIFM=?= =?UTF-8?B?dGF0ZSBEcml2ZSBSZXZpZXcgQCBBUEggIApOZXR3b3Jrcw==?
· Samsung EX2F Camera Review - A Low-Light Advanced Point-And-Shoot For Any Photographer
· NZXT Phantom 630 Ultra Tower
· An MTN News Flash - MEGATech Reviews: Wicked Audio EVAC Full-Size Headphones
· [security-announce] openSUSE-SU-2013:1042-1: critical: kernel: security and bugfix update
· [security-announce] openSUSE-SU-2013:1043-1: critical: kernel
· Fractal Design Arc Midi R2 Case Review
· Mad Catz Cyborg F.R.E.Q. 5 Gaming Headset @ Benchmark Reviews
· News: MSI's Z87-GD65 Gaming motherboard reviewed
· OCZ Vertex 450 256GB SSD Review @ Hardware Canucks

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2671 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3455 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93199 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 185 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6894 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » January 2009 » DSA 1708-1: New Git packages fix remote code execution

DSA 1708-1: New Git packages fix remote code execution

Posted by Bob on: 01/19/2009 10:00 PM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1708-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
January 19, 2009 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : git-core
Vulnerability : shell command injection
Problem type : remote
Debian-specific: no
CVE Id(s) : CVE-2008-5516 CVE-2008-5517
Debian Bug : 512330

It was discovered that gitweb, the web interface for the Git version
control system, contained several vulnerabilities:

Remote attackers could use crafted requests to execute shell commands on
the web server, using the snapshot generation and pickaxe search
functionality (CVE-2008-5516).

Local users with write access to the configuration of a Git repository
served by gitweb could cause gitweb to execute arbitrary shell commands
with the permission of the web server (CVE-2008-5517).

For the stable distribution (etch), these problems have been fixed in
version 1.4.4.4-4+etch1.

For the unstable distribution (sid) and testing distribution (lenny),
the remote shell command injection issuei (CVE-2008-5516) has been fixed
in version 1.5.6-1. The other issue will be fixed soon.

We recommend that you upgrade your Git packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4.orig.tar.gz
Size/MD5 checksum: 1054130 99bc7ea441226f792b6f796a838e7ef0
http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1.diff.gz
Size/MD5 checksum: 88583 47033ef17360b441eb508094a3ab6b2b
http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1.dsc
Size/MD5 checksum: 1097 b907083d358ff2dc892790569fe3a164

Architecture independent packages:

http://security.debian.org/pool/updates/main/g/git-core/gitweb_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 89094 1dc1b790f989600d62ba2d347d890a43
http://security.debian.org/pool/updates/main/g/git-core/git-daemon-run_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 55504 7d1a4bf7bf17f179f94f513fc56f1ffc
http://security.debian.org/pool/updates/main/g/git-core/git-svn_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 100426 149f0e2dda76e4d7613200d530db9e67
http://security.debian.org/pool/updates/main/g/git-core/gitk_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 99598 800ea1d003baf1e348fda3b661fc16ed
http://security.debian.org/pool/updates/main/g/git-core/git-doc_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 453076 4d102f5051116516cf4cc45b10637871
http://security.debian.org/pool/updates/main/g/git-core/git-email_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 62792 201df12660ca0b6180e5fa3c5e0a3543
http://security.debian.org/pool/updates/main/g/git-core/git-arch_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 68508 1489a2af3d016ff8b1a4c612365870b8
http://security.debian.org/pool/updates/main/g/git-core/git-cvs_1.4.4.4-4+etch1_all.deb
Size/MD5 checksum: 94516 afef0aca9b13d1d50af28cbb0d9cc1aa

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_alpha.deb
Size/MD5 checksum: 3101926 6422c5ad17a7248820c3c27195051b0c

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_amd64.deb
Size/MD5 checksum: 2642144 b81b341dce9b234eb193d40decd1283b

arm architecture (ARM)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_arm.deb
Size/MD5 checksum: 2322772 d5c371c8f6f3923edaf880df795870e4

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_hppa.deb
Size/MD5 checksum: 2693958 c519a9e4cfeda0f11fe92e23756c6759

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_i386.deb
Size/MD5 checksum: 2340718 94abafaa8e010240a6a2da50ca717217

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_ia64.deb
Size/MD5 checksum: 3815660 9b0970058eecaf9abd12e5cc472d0434

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_mips.deb
Size/MD5 checksum: 2784146 b345d0ffd96b307025924f99fed33e9e

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_mipsel.deb
Size/MD5 checksum: 2801244 7067901dea12981db4f09e186888e5b3

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_powerpc.deb
Size/MD5 checksum: 2638996 23afd3d0fc61699d0850793c2dbd0047

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_s390.deb
Size/MD5 checksum: 2628016 8f29e9b8b465bf570e8ee7bf78e3437d

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/g/git-core/git-core_1.4.4.4-4+etch1_sparc.deb
Size/MD5 checksum: 2301444 93f43ba8edfb78438a6d7d66b96e4816


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQEcBAEBAgAGBQJJdOgyAAoJEL97/wQC1SS+aaAIAKft8eWfOYqWyNxCeWRoD+v9
Y83tWBlrIoVkEJQqwm/l5L2YVlzZ0uEE7w/OxOVg31SmibwBsnx1OF2IefSmryHe
kUM2TIHfA4/V0kjgs8E1IaQT/3TSRWmSfgQPlUACti4ijsWU/o4pDreyFh+fa0sN
pldwxqxojCo8QVlosJDII8wyZ75DjMlam2UujQAbZrdd7j16SHh/LfZ0vbxTO+PX
mqAOMicVz2b/1IFYjL4YK0NThxvyivtTVT8Nc7nb7As8kUZAF+Uu3yvXFzavObBQ
6Qs6rCThVf+HXE6pDw3MmDU869pfP4H8Irxh6Jy6/2gaJcjNXVqCuCA+v44CJqg=
=6LbJ
-----END PGP SIGNATURE-----


Bookmark and Share

« Steve Jobs to stand for re-election to Disney's board · Videos: Woz on Steve Jobs' leave; parents on Tim Cook's rise »

Linux Compatible » News » January 2009 » DSA 1708-1: New Git packages fix remote code execution
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition