Vulnerability Bulletins |
DSA-3984 git - security update |
|
| Affected software | Debian |
|
joernchen discovered that the git-cvsserver subcommand of Git, adistributed version control system, suffers from a shell commandinjection vulnerability due to unsafe use of the Perl backtickoperator. The git-cvsserver subcommand is reachable from thegit-shell subcommand even if CVS support has not been configured(however, the git-cvs package needs to be installed). More info: https://www.debian.org/security/2017/dsa-3984 |
|






