DSA-4212-1 git -- security update

Related Vulnerabilities: CVE-2018-11235  

Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file. For the oldstable distribution (jessie), this problem has been fixed in version 1:2.1.4-2.1+deb8u6. For the stable distribution (stretch), this problem has been fixed in version 1:2.11.0-3+deb9u3. We recommend that you upgrade your git packages. For the detailed security status of git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/git

Debian Security Advisory

DSA-4212-1 git -- security update

Date Reported:
29 May 2018
Affected Packages:
git
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-11235.
More information:

Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.

For the oldstable distribution (jessie), this problem has been fixed in version 1:2.1.4-2.1+deb8u6.

For the stable distribution (stretch), this problem has been fixed in version 1:2.11.0-3+deb9u3.

We recommend that you upgrade your git packages.

For the detailed security status of git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/git