Debian Security Advisory
DSA-4311-1 git -- security update
- Date Reported:
- 05 Oct 2018
- Affected Packages:
- git
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-17456.
- More information:
-
joernchen of Phenoelit discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability via a specially crafted .gitmodules file in a project cloned with --recurse-submodules.
For the stable distribution (stretch), this problem has been fixed in version 1:2.11.0-3+deb9u4.
We recommend that you upgrade your git packages.
For the detailed security status of git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/git