http://www.mandriva.com/en/
______________________________
Package : git
Date : March 30, 2015
Affected: Business Server 2.0
______________________________
Problem Description:
Updated git packages fix security vulnerability:
It was reported that git, when used as a client on a case-insensitive
filesystem, could allow the overwrite of the .git/config file when
the client performed a git pull. Because git permitted committing
.Git/config (or any case variation), on the pull this would replace the
user's .git/config. If this malicious config file contained defined
external commands (such as for invoking and editor or an external diff
utility) it could allow for the execution of arbitrary code with the
privileges of the user running the git client (CVE-2014-9390).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 2/X86_64:
ef3f480ca48a2a9611bd11fa8a0458
efd3deae08fd17b80008bd3dc881d1
c60432719a43e70eb929c1c75c93fd
10fb62c0748447bd1b960789125e8d
dafec670f61de3e9942a97377b6048
879edb749813e5e175e90c88d2188e
1261450cb657453cd10a055301e42e
8b4e493293c55a955e439233ae55ec
2a4694ce47fe835f532cd7acc734e7
39c2ff102bf754a4ca9a6d9d70fbc7
35bb63e42cfe602a24ae790fe3ddbd
d464e9766d38928a7fe95103823567
644c0f388c821f9192485494ac3199
261134d774a1b833817d8855214a94
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą