|
|
Log in / Subscribe / Register

Ubuntu alert USN-6050-2 (git)

From:  Ian Constantin <ian.constantin@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-6050-2] Git vulnerabilities
Date:  Wed, 17 May 2023 23:18:16 +0300
Message-ID:  <b11effdc-9d40-7d1a-85d5-96c5ac540577@canonical.com>

========================================================================== Ubuntu Security Notice USN-6050-2 May 17, 2023 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-6050-1 fixed several vulnerabilities in Git. This update provides the corresponding updates for CVE-2023-25652 and CVE-2023-29007 on Ubuntu 16.04 LTS. Original advisory details:  It was discovered that Git incorrectly handled certain commands.  An attacker could possibly use this issue to overwrite paths.  (CVE-2023-25652)  André Baptista and Vítor Pinho discovered that Git incorrectly handled  certain configurations. An attacker could possibly use this issue  to achieve arbitrary configuration injection. (CVE-2023-29007) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro):   git                             1:2.7.4-0ubuntu1.10+esm7 In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-6050-2   https://ubuntu.com/security/notices/USN-6050-1   CVE-2023-25652, CVE-2023-29007


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds