UbuntuUpdates.org

Package "cgit"

Name: cgit

Description:

hyperfast web frontend for git repositories written in C

Latest version: 1.1+git2.10.2-3ubuntu0.1
Release: bionic (18.04)
Level: updates
Repository: universe
Homepage: https://git.zx2c4.com/cgit/

Links


Download "cgit"


Other versions of "cgit" in Bionic

Repository Area Version
base universe 1.1+git2.10.2-3build1
security universe 1.1+git2.10.2-3ubuntu0.1

Changelog

Version: 1.1+git2.10.2-3ubuntu0.1 2018-08-17 02:33:43 UTC

  cgit (1.1+git2.10.2-3ubuntu0.1) bionic-security; urgency=high

  * SECURITY UPDATE: Directory traversal vulnerability.
    - d/p/clone-fix-directory-traversal.patch:
      This fixes a directory traversal vulnerability in CGit
      before 1.2.1 when `enable-http-clone=1` is not turned off,
      as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.
    - CVE-2018-14912 (LP: #1787021)

 -- Unit 193 <email address hidden> Tue, 14 Aug 2018 15:57:15 -0400

1787021 Directory traversal vulnerability
CVE-2018-14912 cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cg



About   -   Send Feedback to @ubuntu_updates