Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2023.0533 git security update 30 January 2023 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: git Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2022-41903 CVE-2022-39260 CVE-2022-39253 CVE-2022-29187 CVE-2022-24765 CVE-2022-23521 Original Bulletin: https://lists.debian.org/debian-security-announce/2023/msg00022.html Comment: CVSS (Max): 9.8 CVE-2022-41903 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVSS Source: NVD Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-5332-1 security@debian.org https://www.debian.org/security/ Aron Xu January 29, 2023 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : git CVE ID : CVE-2022-23521 CVE-2022-24765 CVE-2022-29187 CVE-2022-39253 CVE-2022-39260 CVE-2022-41903 Debian Bug : 1014848 1022046 1029114 Multiple issues were found in Git, a distributed revision control system. An attacker may trigger remote code execution, cause local users into executing arbitrary commands, leak information from the local filesystem, and bypass restricted shell. This update includes two changes of behavior that may affect certain setup: - It stops when directory traversal changes ownership from the current user while looking for a top-level git directory, a user could make an exception by using the new safe.directory configuration. - The default of protocol.file.allow has been changed from "always" to "user". For the stable distribution (bullseye), these problems have been fixed in version 1:2.30.2-1+deb11u1. We recommend that you upgrade your git packages. For the detailed security status of git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/git Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ - -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEhhz+aYQl/Bp4OTA7O1LKKgqv2VQFAmPWoBQACgkQO1LKKgqv 2VQ9Ugf/amidAHmXSaPDpk9Hs52ttiUPJ6uMJRYyJI/KQ3o5eoQfdzYmVT9ACsuK XxT7Xd5JqkHZMJyABeqm42JJgOiyV5GUx2ZrsQ3M5UE2HD2keWxaJmrkj6VlzkFs qHOynAgprllBmw3RfHkyjybQEG4dtmiLk5+gJZK0MYxAaKzyeNi7dnLEllYOf+Xi dn3aSk8edTVqT80jdMIfBeOn1f/Zb+9kSHyVOezku1NfYES1dnA7RaOAkKmw/JkR HYnuxpdAfkb2K1z6LmDkLWpTQU7CbOPcPpWBWgkuD6tQmKjppx5MYuDZ+hW0y6aV EI1gHfi7qbZ3+b+nxEa9CTvap0d8QA== =Vh4D - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBY9chackNZI30y1K9AQga0hAAl5jVtRHXLKL8J/Atc3XRj3nUUjoRJB2d Ta3wewebTS0cblM6g2cxn9EZNOiQqyr32t+9eGkvCMpYC8VEc87pkgd79WhO7U8Y 5vu337+EYBNr4DYt3HieEler1eayQEmQ6Sg+q8e371assFJ976OPTscRyUer5ytT RZ601B+eAlgu2Yh4odv/nvPsJOjXNJFJqdYe49s+hgA2reqsemcEuWn5hVoeRpcM xSh24ZDRoZGUPgydbrDGW/q2ok5DiyZyMd4EtM9eaStrkWFXdSQc/lTa3VqxGUxT Z41muwSdy3PqfFvS/LSUbVrc7sVNJezZ8YzhcLWFgarWycMFlsE4+4MGjr6UPp9B /uokxtOr/nifWLy/vVwwn2EJXJ4vfYYwwDA1J2Oxz3zuzEY6F74Dx0fsS/FY5no0 EDMbiBVW9niIAww/FchfSZW6XdStCA0YUFmp510z4Nc0unfkcGiDVHdiIVvmY9GN E48S1AON5Oj4+VAkQIk17CGZIUmAsijf2sdVh/T2krVO4da5zfspR5iJ3CDOId4W eUV3/lyHnVIQIiy0/Pc8tkRjXTCeuNuuqNsMVtVdXtF/wLdULRVmDv9egyKcyA2O 8j1BTFUthNjfpinvIwh0/jFSXOVZgLaSSi9iba+KfZAnGY+0oCQ1+boZAxK1XrTQ dxuqskjrEP8= =Qt6R -----END PGP SIGNATURE-----