[Bug 1404035] [NEW] Errors in handling case-sensitive directories allow for remote code execution on pull
Luke Faraone
luke at faraone.cc
Thu Dec 18 22:36:41 UTC 2014
*** This bug is a security vulnerability ***
Public security bug reported:
>From the upstream announcement[1]:
This is a security-fix for CVE-2014-9390, which affects users on
Windows and Mac OS X but not typical UNIX users. A set of new
releases for older maintenance tracks (v1.8.5.6, v1.9.5, v2.0.5, and
v2.1.4) are published at the same time and they contain the same fix.
Various implementations and ports, including Git for Windows, Git OS
X installer, JGit & EGit, libgit2 (and Visual Studio which uses it)
have been updated at the same time.
Even though the issue may not affect Linux users, if you are a
hosting service whose users may fetch from your service to Windows
or Mac OS X machines, you are strongly encouraged to update to
protect such users who use existing versions of Git.
This issue also affects hg[2].
[1]: http://article.gmane.org/gmane.linux.kernel/1853266
[2]: http://mercurial.selenic.com/wiki/WhatsNew#Mercurial_3.2.3_.282014-12-18.29
** Affects: git (Ubuntu)
Importance: High
Status: New
** Affects: mercurial (Ubuntu)
Importance: High
Status: New
** Changed in: git (Ubuntu)
Importance: Undecided => High
** Information type changed from Public to Public Security
** Also affects: mercurial (Ubuntu)
Importance: Undecided
Status: New
** Changed in: mercurial (Ubuntu)
Importance: Undecided => High
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to git in Ubuntu.
https://bugs.launchpad.net/bugs/1404035
Title:
Errors in handling case-sensitive directories allow for remote code
execution on pull
Status in git package in Ubuntu:
New
Status in mercurial package in Ubuntu:
New
Bug description:
From the upstream announcement[1]:
This is a security-fix for CVE-2014-9390, which affects users on
Windows and Mac OS X but not typical UNIX users. A set of new
releases for older maintenance tracks (v1.8.5.6, v1.9.5, v2.0.5, and
v2.1.4) are published at the same time and they contain the same fix.
Various implementations and ports, including Git for Windows, Git OS
X installer, JGit & EGit, libgit2 (and Visual Studio which uses it)
have been updated at the same time.
Even though the issue may not affect Linux users, if you are a
hosting service whose users may fetch from your service to Windows
or Mac OS X machines, you are strongly encouraged to update to
protect such users who use existing versions of Git.
This issue also affects hg[2].
[1]: http://article.gmane.org/gmane.linux.kernel/1853266
[2]: http://mercurial.selenic.com/wiki/WhatsNew#Mercurial_3.2.3_.282014-12-18.29
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/git/+bug/1404035/+subscriptions
More information about the foundations-bugs
mailing list