-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3502-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler July 25, 2023 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : python-git Version : 2.1.11-1+deb10u1 CVE ID : CVE-2022-24439 Debian Bug : 1027163 Sam Wheating discovered that python-git, a Python library to interact with Git repositories, is vulnerable to shell injection due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. For Debian 10 buster, this problem has been fixed in version 2.1.11-1+deb10u1. We recommend that you upgrade your python-git packages. For the detailed security status of python-git please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-git Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmS/n+EACgkQDTl9HeUl XjB23w//d+eU+w3R7+FCCGa8Tw1IoUzBxZjFMmNBVyPNIQ+zrGiluaEqWcziSf0p +SHGCCnAP4fmktU3s96RBVdeHUf+aHnDsB3YVe49N+OU3YR0Qjnyus3Kz/xlN7wR X4wewF2fAjeji1uj2LiWvInQQHjI1fmRdUYXa/x46Bc4tAxUoEzasNNn+noLzsSh J+Kstw/tY42x40wIj15UR3mL7VghpFFL7hsGkSp9Vrb980NDwUtSjvcF99qM6ly0 H3eI06eX9r5r+hshzj5PvUhBMyli5vprZ4zhuzSJIMb4NfIvCP0JvK6ItHqsVFO+ 00LhEm/Q18Iv2mxqEA+vmWUg5R1Rj2XfI1sA88/ER749eqh67v9Lm5ruDqoczQky ICGKN/ZPJxNdqBPnizwAfXXYnvpWsz0vu/9Q+R22Ux2NF90T9eohfy/lUDZdmu9l IsUq61z6FzAC+aRzBSSZk6kpeZKtzNvZFyY36nbPlZAtQGQRZBLv4Hp7mo4GKrHu J8l39wbLhndL0wwgZ6Z/yZ9Lno2KTmFbX/+0R7Dl6CG2OGM0Ituz6jgOu70YjOO8 p6gBkf93SsyZdIU34KF1AYerCzLXNBYY1Z5xQl0YV3rrv+wIGfnez7IFe6NcfZ5f 3PPjezFM5moy4uInmgkCraywTef+0VhAm5S5emmE6vMcMciLHuA= =7ZsA -----END PGP SIGNATURE-----