Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 255567 (CVE-2008-5517) - www-apps/gitweb<1.6.0.6 remote code execution (CVE-2008-{5516,5517,5916})
Summary: www-apps/gitweb<1.6.0.6 remote code execution (CVE-2008-{5516,5517,5916})
Status: RESOLVED DUPLICATE of bug 251343
Alias: CVE-2008-5517
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://repo.or.cz/w/git.git?a=commit;...
Whiteboard: ~1 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-01-19 23:38 UTC by Stefan Behte (RETIRED)
Modified: 2009-02-12 18:30 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-01-19 23:38:14 UTC
CVE-2008-5517 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5517):
  The web interface in git in SUSE openSUSE 10.3 allows remote
  attackers to execute arbitrary commands via shell metacharacters in
  an unspecified context.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-24 22:09:06 UTC
CVE-2008-5516 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5516):
  The web interface in git (gitweb) 1.5.6, and possibly other versions,
  allows remote attackers to execute arbitrary commands via shell
  metacharacters related to git_search.  NOTE: because of the lack of
  details, it is not clear whether CVE-2008-5516 and CVE-2008-5517 are
  distinct issues on the rPath Linux 2 platform.

CVE-2008-5916 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5916):
  gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x
  before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and
  other versions after 1.4.3 allows local repository owners to execute
  arbitrary commands by modifying the diff.external configuration
  variable and executing a crafted gitweb query.

Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-02-12 18:30:50 UTC

*** This bug has been marked as a duplicate of bug 251343 ***