Debian Security Advisory 3984-1

Discussion in 'News Aggregator' started by Packet Storm, 28 Sep 2017.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3984-1 - joernchen discovered that the git-cvsserver subcommand of Git, a distributed version control system, suffers from a shell command injection vulnerability due to unsafe use of the Perl backtick operator. The git-cvsserver subcommand is reachable from the git-shell subcommand even if CVS support has not been configured (however, the git-cvs package needs to be installed).

    Continue reading...
     

Share This Page

Loading...