CVE-2008-5916
Publication date 21 January 2009
Last updated 24 July 2024
Ubuntu priority
gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and executing a crafted gitweb query.
Status
Package | Ubuntu Release | Status |
---|---|---|
git-core | ||
Notes
mdeslaur
diff.external variable only available since 1.5.4 http://repo.or.cz/w/git.git?a=commitdiff;h=cbe02100 http://marc.info/?l=linux-kernel&m=122977048914639&w=2 So, doesn't affect dapper and gutsy
Patch details
Package | Patch details |
---|---|
git-core |
References
Related Ubuntu Security Notices (USN)
- USN-723-1
- Git vulnerabilities
- 18 February 2009