LWN.net Logo

git: information disclosure

Package(s):git CVE #(s):CVE-2013-0308
Created:March 4, 2013 Updated:March 18, 2013
Description: From the Red Hat advisory:

It was discovered that Git's git-imap-send command, a tool to send a collection of patches from standard input (stdin) to an IMAP folder, did not properly perform SSL X.509 v3 certificate validation on the IMAP server's certificate, as it did not ensure that the server's hostname matched the one provided in the CN field of the server's certificate. A rogue server could use this flaw to conduct man-in-the-middle attacks, possibly leading to the disclosure of sensitive information.

Alerts:
openSUSE openSUSE-SU-2013:0380-1 2013-03-01
openSUSE openSUSE-SU-2013:0382-1 2013-03-01
Fedora FEDORA-2013-2829 2013-03-02
Fedora FEDORA-2013-2763 2013-03-02
Red Hat RHSA-2013:0589-01 2013-03-04
Scientific Linux SL-git-20130304 2013-03-04
Oracle ELSA-2013-0589 2013-03-04
CentOS CESA-2013:0589 2013-03-09
Mageia MGASA-2013-0091 2013-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds