SB2018112918 - Command injection in git (Alpine package)
Published: November 29, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Command injection (CVE-ID: CVE-2018-19486)
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists due to a flaw in the run_command() API and 'run-command.c' when handling malicious input. A remote attacker can issue specially crafted commands from the current working directory and execute arbitrary commands on the target system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=64bd4efee3d96f4ad333d07b0fabc16320dd2f29
- https://git.alpinelinux.org/aports/commit/?id=330dccaf7a87b0e784100ef5e2fa7f99b72c84d9
- https://git.alpinelinux.org/aports/commit/?id=1ca69220c2d5812e00069f528ace94bbb8fb2c6a
- https://git.alpinelinux.org/aports/commit/?id=4f5598e37777d626dcab46970b984f4e07e56135
- https://git.alpinelinux.org/aports/commit/?id=77ebb2a9270d15652313ccf62a06fd2960b8b9ba