USN-3671-1
Dashboard / Vulnerabilities / USN-3671-1
USN-3671-1
Summary: git vulnerabilities
Details: Etienne Stalmans discovered that git did not properly validate git submodules files. A remote attacker could possibly use this to craft a git repo that causes arbitrary code execution when "git clone --recurse-submodules" is used. (CVE-2018-11235) It was discovered that an integer overflow existed in git's pathname consistency checking code when used on NTFS filesystems. An attacker could use this to cause a denial of service or expose sensitive information. (CVE-2018-11233)
References: https://ubuntu.com/security/notices/USN-3671-1, https://ubuntu.com/security/CVE-2018-11233, https://ubuntu.com/security/CVE-2018-11235
Affected packages
Package
Name: git
Purl: pkg:deb/ubuntu/git@1:1.9.1-1ubuntu0.8?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
