Gentoo Archives: gentoo-announce

From: Sergey Popov <pinkbyte@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201401-06 ] Git: Privilege escalation
Date: Fri, 10 Jan 2014 14:01:11
Message-Id: 52CFFCC5.7030606@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201401-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Git: Privilege escalation
9 Date: January 10, 2014
10 Bugs: #335891
11 ID: 201401-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A stack-based buffer overflow in Git might allow a local attacker to
19 gain escalated privileges.
20
21 Background
22 ==========
23
24 Git is a free and open source distributed version control system
25 designed to handle everything from small to very large projects with
26 speed and efficiency.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 dev-vcs/git < 1.7.2.2 >= 1.7.2.2
35
36 Description
37 ===========
38
39 Git contains a stack-based buffer overflow in the is_git_directory
40 function in setup.c.
41
42 Impact
43 ======
44
45 A local attacker could gain escalated privileges via a specially
46 crafted git repository.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Git users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=dev-vcs/git-1.7.2.2"
60
61 NOTE: This is a legacy GLSA. Updates for all affected architectures are
62 available since September 11, 2010. It is likely that your system is
63 already no longer affected by this issue.
64
65 References
66 ==========
67
68 [ 1 ] CVE-2010-2542
69 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2542
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-201401-06.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users' machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 https://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2014 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature