gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.
References
Link | Resource |
---|---|
https://github.com/sitaramc/gitolite/commit/3dad4f8e3214d6ab5f71823019a624fa48b055a3 | Patch Third Party Advisory |
https://groups.google.com/forum/#%21topic/gitolite/Tu1sjaf7A4A/discussion | |
https://www.openwall.com/lists/oss-security/2013/10/21/11 | Mailing List Patch |
https://www.securityfocus.com/bid/63237 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2018-09-21T17:00:00
Updated: 2018-09-21T16:57:01
Reserved: 2013-06-12T00:00:00
Link: CVE-2013-4451
JSON object: View
NVD Information
Status : Modified
Published: 2018-09-21T17:29:00.420
Modified: 2023-11-07T02:16:17.940
Link: CVE-2013-4451
JSON object: View
Redhat Information
No data.
CWE