Oval Definition:oval:org.mitre.oval:def:12253
Revision Date:2014-07-21Version:20
Title:DSA-2215-1 gitolite -- directory traversal
Description:Dylan Simon discovered that gitolite, a SSH-based gatekeeper for git repositories, is prone to directory traversal attacks when restricting admin defined commands. This allows an attacker to execute arbitrary commands with privileges of the gitolite server via crafted command names. Please note that this only affects installations that have ADC enabled. The oldstable distribution is not affected by this problem, it does not include gitolite.
Family:unixClass:patch
Status:ACCEPTEDReference(s):DSA-2215-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):gitolite
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND Installed architecture is all
  • AND gitolite DPKG is earlier than 1.5.4-2+squeeze1
  • BACK