gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and executing a crafted gitweb query.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/47528 | vdb entry |
http://www.openwall.com/lists/oss-security/2009/01/20/2 | mailing list |
http://osvdb.org/50918 | vdb entry |
http://secunia.com/advisories/33282 | third party advisory |
http://www.gentoo.org/security/en/glsa/glsa-200903-15.xml | vendor advisory |
http://secunia.com/advisories/34194 | third party advisory |
http://secunia.com/advisories/33964 | third party advisory |
http://www.openwall.com/lists/oss-security/2009/01/15/2 | mailing list |
http://marc.info/?l=linux-kernel&m=122975564100863&w=2: | mailing list |
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01169.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01170.html | vendor advisory |
http://securityreason.com/securityalert/4922 | third party advisory |
http://marc.info/?l=git&m=122975564100860&w=2 | mailing list |
http://www.ubuntu.com/usn/USN-723-1 | vendor advisory |