Oval Definition:oval:com.redhat.rhsa:def:20101003
Revision Date:2010-12-21Version:636
Title:RHSA-2010:1003: git security update (Moderate)
Description:Git is a fast, scalable, distributed revision control system.

  • A cross-site scripting (XSS) flaw was found in gitweb, a simple web interface for Git repositories. A remote attacker could perform an XSS attack against victims by tricking them into visiting a specially-crafted gitweb URL. (CVE-2010-3906)

    All gitweb users should upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-3906
    CVE-2010-3906
    RHSA-2010:1003
    RHSA-2010:1003-01
    RHSA-2010:1003-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • emacs-git is earlier than 0:1.7.1-2.el6_0.1
  • AND emacs-git is signed with Red Hat redhatrelease2 key
  • emacs-git-el is earlier than 0:1.7.1-2.el6_0.1
  • AND emacs-git-el is signed with Red Hat redhatrelease2 key
  • git is earlier than 0:1.7.1-2.el6_0.1
  • AND git is signed with Red Hat redhatrelease2 key
  • git-all is earlier than 0:1.7.1-2.el6_0.1
  • AND git-all is signed with Red Hat redhatrelease2 key
  • git-cvs is earlier than 0:1.7.1-2.el6_0.1
  • AND git-cvs is signed with Red Hat redhatrelease2 key
  • git-daemon is earlier than 0:1.7.1-2.el6_0.1
  • AND git-daemon is signed with Red Hat redhatrelease2 key
  • git-email is earlier than 0:1.7.1-2.el6_0.1
  • AND git-email is signed with Red Hat redhatrelease2 key
  • git-gui is earlier than 0:1.7.1-2.el6_0.1
  • AND git-gui is signed with Red Hat redhatrelease2 key
  • git-svn is earlier than 0:1.7.1-2.el6_0.1
  • AND git-svn is signed with Red Hat redhatrelease2 key
  • gitk is earlier than 0:1.7.1-2.el6_0.1
  • AND gitk is signed with Red Hat redhatrelease2 key
  • gitweb is earlier than 0:1.7.1-2.el6_0.1
  • AND gitweb is signed with Red Hat redhatrelease2 key
  • perl-Git is earlier than 0:1.7.1-2.el6_0.1
  • AND perl-Git is signed with Red Hat redhatrelease2 key
  • BACK