![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.1.1.2010.2114 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DSA-2114-1) |
Summary: | The remote host is missing an update for the Debian 'git-core' package(s) announced via the DSA-2114-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'git-core' package(s) announced via the DSA-2114-1 advisory. Vulnerability Insight: The Debian stable point release 5.0.6 included updated packages of the Git revision control system in order to fix a security issue. Unfortunately, the update introduced a regression which could make it impossible to clone or create Git repositories. This upgrade fixes this regression, which is tracked as Debian bug #595728. The original security issue allowed an attacker to execute arbitrary code if he could trick a local user to execute a git command in a crafted working directory (CVE-2010-2542). For the stable distribution (lenny), this problem has been fixed in version 1.5.6.5-3+lenny3.2. The packages for the hppa architecture are not included in this advisory. However, the hppa architecture is not known to be affected by the regression. For the testing distribution (squeeze) and the unstable distribution (sid), the security issue has been fixed in version 1.7.1-1.1. These distributions were not affected by the regression. We recommend that you upgrade your git-core packages. Affected Software/OS: 'git-core' package(s) on Debian 5. Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2542 41891 http://www.securityfocus.com/bid/41891 43457 http://secunia.com/advisories/43457 ADV-2011-0464 http://www.vupen.com/english/advisories/2011/0464 SUSE-SR:2011:004 http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html [oss-security] 20100721 CVE request: git http://www.openwall.com/lists/oss-security/2010/07/22/1 [oss-security] 20100722 Re: CVE request: git http://www.openwall.com/lists/oss-security/2010/07/22/4 http://git.kernel.org/?p=git/git.git%3Ba=commit%3Bh=3c9d0414ed2db0167e6c828b547be8fc9f88fccc http://www.kernel.org/pub/software/scm/git/docs/RelNotes-1.7.2.1.txt https://bugzilla.redhat.com/show_bug.cgi?id=618108 |
Copyright | Copyright (C) 2023 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |