Vulnerability Bulletins

DSA-3984 git - security update

   
Affected software Debian
 
joernchen discovered that the git-cvsserver subcommand of Git, adistributed version control system, suffers from a shell commandinjection vulnerability due to unsafe use of the Perl backtickoperator. The git-cvsserver subcommand is reachable from thegit-shell subcommand even if CVS support has not been configured(however, the git-cvs package needs to be installed).

More info:

https://www.debian.org/security/2017/dsa-3984