Directory traversal vulnerability
Bug #1787021 reported by
Unit 193
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cgit (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Xenial |
New
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
Undecided
|
Steve Beattie |
Bug Description
Howdy,
The CVE says: "cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-
This has been fixed upstream with https:/
This was fixed in Debian unstable: https:/
CVE References
information type: | Public → Public Security |
Changed in cgit (Ubuntu): | |
status: | New → In Progress |
assignee: | nobody → Steve Beattie (sbeattie) |
status: | In Progress → Fix Released |
Changed in cgit (Ubuntu Xenial): | |
status: | New → In Progress |
assignee: | nobody → Steve Beattie (sbeattie) |
Changed in cgit (Ubuntu): | |
assignee: | Steve Beattie (sbeattie) → nobody |
Changed in cgit (Ubuntu Bionic): | |
status: | New → In Progress |
Changed in cgit (Ubuntu Xenial): | |
status: | In Progress → New |
assignee: | Steve Beattie (sbeattie) → nobody |
Changed in cgit (Ubuntu Bionic): | |
assignee: | nobody → Steve Beattie (sbeattie) |
To post a comment you must log in.
I've attached two versions of this patch, one is based off the Bionic upload, the other backports the minimal NMU that cosmic has. I personally prefer the latter.