Bugzilla – Bug 1121570
VUL-1: CVE-2018-20683: gitolite: commands/rsync mishandles the rsync command line
Last modified: 2019-01-17 23:38:27 UTC
CVE-2018-20683 commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20683 https://bugs.debian.org/918849 https://groups.google.com/forum/#!topic/gitolite-announce/6xbjjmpLePQ https://github.com/sitaramc/gitolite/commit/5df2b817255ee919991da6c310239e08c8fcc1ae https://github.com/sitaramc/gitolite/blob/master/CHANGELOG
ongoing work
This is an autogenerated message for OBS integration: This bug (1121570) was mentioned in https://build.opensuse.org/request/show/665994 Factory / gitolite https://build.opensuse.org/request/show/666001 15.0+42.3+Backports:SLE-15 / gitolite
done
openSUSE-SU-2019:0054-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1121570 CVE References: CVE-2018-20683 Sources used: openSUSE Leap 42.3 (src): gitolite-3.6.11-4.6.1 openSUSE Leap 15.0 (src): gitolite-3.6.11-lp150.2.6.1 openSUSE Backports SLE-15 (src): gitolite-3.6.11-bp150.3.6.1