Mageia alert MGASA-2016-0047 (cgit)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2016-0047: Updated cgit packages fix security vulnerability | |
| Date: | Fri, 5 Feb 2016 18:26:48 +0100 | |
| Message-ID: | <20160205172648.7A15B21BE3B@valstar.mageia.org> |
MGASA-2016-0047 - Updated cgit packages fix security vulnerability Publication date: 05 Feb 2016 URL: http://advisories.mageia.org/MGASA-2016-0047.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-1899, CVE-2016-1900, CVE-2016-1901 Description: Reflected Cross Site Scripting and Header Injection in Mimetype Query String in cgit before 0.12 (CVE-2016-1899). Stored Cross Site Scripting and Header Injection in Filename Parameter in cgit before 0.12 (CVE-2016-1900). Integer Overflow resulting in Buffer Overflow in cgit before 0.12 (CVE-2016-1901). References: - https://bugs.mageia.org/show_bug.cgi?id=17495 - http://lists.opensuse.org/opensuse-updates/2016-01/msg000... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1899 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1900 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1901 SRPMS: - 5/core/cgit-0.12-1.mga5
