Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.1.2010.2114
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2114-1)
Summary:The remote host is missing an update for the Debian 'git-core' package(s) announced via the DSA-2114-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'git-core' package(s) announced via the DSA-2114-1 advisory.

Vulnerability Insight:
The Debian stable point release 5.0.6 included updated packages of the Git revision control system in order to fix a security issue. Unfortunately, the update introduced a regression which could make it impossible to clone or create Git repositories. This upgrade fixes this regression, which is tracked as Debian bug #595728.

The original security issue allowed an attacker to execute arbitrary code if he could trick a local user to execute a git command in a crafted working directory (CVE-2010-2542).

For the stable distribution (lenny), this problem has been fixed in version 1.5.6.5-3+lenny3.2.

The packages for the hppa architecture are not included in this advisory. However, the hppa architecture is not known to be affected by the regression.

For the testing distribution (squeeze) and the unstable distribution (sid), the security issue has been fixed in version 1.7.1-1.1. These distributions were not affected by the regression.

We recommend that you upgrade your git-core packages.

Affected Software/OS:
'git-core' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-2542
41891
http://www.securityfocus.com/bid/41891
43457
http://secunia.com/advisories/43457
ADV-2011-0464
http://www.vupen.com/english/advisories/2011/0464
SUSE-SR:2011:004
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html
[oss-security] 20100721 CVE request: git
http://www.openwall.com/lists/oss-security/2010/07/22/1
[oss-security] 20100722 Re: CVE request: git
http://www.openwall.com/lists/oss-security/2010/07/22/4
http://git.kernel.org/?p=git/git.git%3Ba=commit%3Bh=3c9d0414ed2db0167e6c828b547be8fc9f88fccc
http://www.kernel.org/pub/software/scm/git/docs/RelNotes-1.7.2.1.txt
https://bugzilla.redhat.com/show_bug.cgi?id=618108
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.