[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3502-1] python-git security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3502-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Sylvain Beucler
July 25, 2023                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : python-git
Version        : 2.1.11-1+deb10u1
CVE ID         : CVE-2022-24439
Debian Bug     : 1027163

Sam Wheating discovered that python-git, a Python library to interact
with Git repositories, is vulnerable to shell injection due to
improper user input validation, which makes it possible to inject a
maliciously crafted remote URL into the clone command.

For Debian 10 buster, this problem has been fixed in version
2.1.11-1+deb10u1.

We recommend that you upgrade your python-git packages.

For the detailed security status of python-git please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-git

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmS/n+EACgkQDTl9HeUl
XjB23w//d+eU+w3R7+FCCGa8Tw1IoUzBxZjFMmNBVyPNIQ+zrGiluaEqWcziSf0p
+SHGCCnAP4fmktU3s96RBVdeHUf+aHnDsB3YVe49N+OU3YR0Qjnyus3Kz/xlN7wR
X4wewF2fAjeji1uj2LiWvInQQHjI1fmRdUYXa/x46Bc4tAxUoEzasNNn+noLzsSh
J+Kstw/tY42x40wIj15UR3mL7VghpFFL7hsGkSp9Vrb980NDwUtSjvcF99qM6ly0
H3eI06eX9r5r+hshzj5PvUhBMyli5vprZ4zhuzSJIMb4NfIvCP0JvK6ItHqsVFO+
00LhEm/Q18Iv2mxqEA+vmWUg5R1Rj2XfI1sA88/ER749eqh67v9Lm5ruDqoczQky
ICGKN/ZPJxNdqBPnizwAfXXYnvpWsz0vu/9Q+R22Ux2NF90T9eohfy/lUDZdmu9l
IsUq61z6FzAC+aRzBSSZk6kpeZKtzNvZFyY36nbPlZAtQGQRZBLv4Hp7mo4GKrHu
J8l39wbLhndL0wwgZ6Z/yZ9Lno2KTmFbX/+0R7Dl6CG2OGM0Ituz6jgOu70YjOO8
p6gBkf93SsyZdIU34KF1AYerCzLXNBYY1Z5xQl0YV3rrv+wIGfnez7IFe6NcfZ5f
3PPjezFM5moy4uInmgkCraywTef+0VhAm5S5emmE6vMcMciLHuA=
=7ZsA
-----END PGP SIGNATURE-----


Reply to: