Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Git: Denial of Service
Posted by Benjamin D. Thomas
malicious people to cause a DoS (Denial of Service).
--==============40019248=Content-Type: multipart/alternative; boundary 1636c5b8ef5b8986046d1776c5
--001636c5b8ef5b8986046d1776c5
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-92 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-06-24
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
======
A vulnerability has been reported in Git, which can be exploited by
malicious people to cause a DoS (Denial of Service).
Description
==========
The vulnerability is caused due to an infinite loop when parsing certain
additional request parameters. This can be exploited to cause a high CPU
load by sending specially crafted requests to an affected git-daemon.
Affected packages:
Pardus 2008:
git, all before 1.6.2-78-14
git-emacs, all before 1.6.2-78-14
gitweb, all before 1.6.2-78-14
Resolution
=========
There are update(s) for git, git-emacs, gitweb. You can update them via
Package Manager or with a single command from console:
pisi up git git-emacs gitweb
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id011
* http://git.kernel.org/?p=git/git.git;a=commitdiff;hsbb33a9
* http://secunia.com/advisories/35437