stable

git-2.13.5-1.fc26

FEDORA-2017-b1b3ae6666 created by tmz 7 years ago for Fedora 26

Resolve an arbitrary code execution vulnerability via crafted "ssh://" URL (CVE-2017-1000117).

From the release announcement:

A malicious third-party can give a crafted "ssh://..." URL to an
unsuspecting victim, and an attempt to visit the URL can result in
any program that exists on the victim's machine being executed.
Such a URL could be placed in the .gitmodules file of a malicious
project, and an unsuspecting victim could be tricked into running
"git clone --recurse-submodules" to trigger the vulnerability.

Credits to find and fix the issue go to Brian Neel at GitLab, Joern
Schneeweisz of Recurity Labs and Jeff King at GitHub.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2017-b1b3ae6666

This update has been submitted for testing by tmz.

7 years ago

This update has been pushed to testing.

7 years ago
User Icon pwalter commented & provided feedback 7 years ago
karma

Works

User Icon chr77 commented & provided feedback 7 years ago
karma

Works for me. No regressions noted compared to previous version.

User Icon cserpentis commented & provided feedback 7 years ago
karma

works for me

This update has been submitted for stable by bodhi.

7 years ago

This update has been pushed to stable.

7 years ago
User Icon brandongray commented & provided feedback 7 years ago
karma

LGTM

BZ#1480386 CVE-2017-1000117 git: Command injection via malicious ssh URLs

Please login to add feedback.

Metadata
Type
security
Severity
high
Karma
4
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
7 years ago
in testing
7 years ago
in stable
7 years ago
BZ#1480386 CVE-2017-1000117 git: Command injection via malicious ssh URLs
0
1

Automated Test Results