Security update for cgit
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:0218-1
Final
1
1
2016-01-24T14:46:46Z
current
2016-01-24T14:46:46Z
2016-01-24T14:46:46Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for cgit
This update to cgit 0.12 fixes the following issues:
- CVE-2016-1899: Reflected Cross Site Scripting and Header Injection in Mimetype Query String
- CVE-2016-1900: Stored Cross Site Scripting and Header Injection in Filename Parameter
- CVE-2016-1901: Integer Overflow resulting in Buffer Overflow
The bundled git version was updated to 2.7.0.
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
https://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
E-Mail link for openSUSE-SU-2016:0218-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
cgit-0.12-11.6.1
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a request to blob/cgit.c.
CVE-2016-1899
moderate
Please Install the update.
https://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
https://www.suse.com/security/cve/CVE-2016-1899.html
CVE-2016-1899
https://bugzilla.suse.com/961916
SUSE Bug 961916
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.
CVE-2016-1900
moderate
Please Install the update.
https://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
https://www.suse.com/security/cve/CVE-2016-1900.html
CVE-2016-1900
https://bugzilla.suse.com/961916
SUSE Bug 961916
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
CVE-2016-1901
moderate
Please Install the update.
https://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
https://www.suse.com/security/cve/CVE-2016-1901.html
CVE-2016-1901
https://bugzilla.suse.com/961916
SUSE Bug 961916