LWN.net Logo

gitolite: directory traversal vulnerability

Package(s):gitolite3 CVE #(s):CVE-2012-4506
Created:October 24, 2012 Updated:October 24, 2012
Description: From the CVE: Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
Alerts:
Fedora FEDORA-2012-15746 2012-10-18
Fedora FEDORA-2012-15731 2012-10-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds