Friday, February 3, 2023
  • Login
No Result
View All Result
Atreju
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
No Result
View All Result
Atreju
No Result
View All Result
ADVERTISEMENT
Home Technology

Git patches two critical remote code execution security flaws

by Atreju
January 19, 2023
in Technology
0
Red padlock open on electric circuits network dark red background
0
SHARES
7
VIEWS
Share on FacebookShare on Twitter

Cybersecurity researchers from X41 and GitLab has discovered three high-severity vulnerabilities in the Git distributed version control system.

The flaws could have allowed threat actors to run arbitrary code on target endpoints by exploiting heap-based buffer overflow vulnerabilities, the researchers said. Of the three flaws, two already have patches lined up, while a workaround is available for the third one.

The two vulnerabilities that were patched are tracked as CVE-2022-41903 and CVE-2022-23521. Developers (opens in new tab) looking to protect their devices should update Git to version 2.30.7. The third one is tracked as CVE-2022-41953, with the workaround being not using the Git GUI software to clone repositories. Another way to stay safe, according to BleepingComputer, is to avoid cloning from untrusted sources altogether.

Patches and workarounds

“The most severe issue discovered allows an attacker to trigger a heap-based memory corruption during clone or pull operations, which might result in code execution. Another critical issue allows code execution during an archive operation, which is commonly performed by Git forges,” the researchers said (opens in new tab) in their explanation of the incident.

“Additionally, a huge number of integer related issues was identified which may lead to denial-of-service situations, out-of-bound reads or simply badly handled corner cases on large input.”

Git has since released a couple of additional versions, so to be on the safe side, make sure you’re running the latest version of Git – 2.39.1.

BleepingComputer notes that those that cannot apply the patch immediately should disable “git archive” in untrusted repositories, or avoid running the command on untrusted repositories. Furthermore, if “git archive” is exposed via “git daemon”, users should disable it when working with untrusted depositories. This can be done through the “git config –global daemon.upladArch false” command, it said.

“We strongly recommend that all installations running a version affected by the issues [..] are upgraded to the latest version as soon as possible,” GitLab warned (opens in new tab).

Via: BleepingComputer (opens in new tab)

Atreju

Atreju

Next Post
Murray, quasi 6 ore per battere Kokkinakis all'Australian Open: il match finisce alle 4:05 del mattino

Murray, quasi 6 ore per battere Kokkinakis all'Australian Open: il match finisce alle 4:05 del mattino

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Yuzvendra Chahal Wiki Biography, Early Life, Career, Family, Girlfriend, Profession, Education, Earnings

Yuzvendra Chahal Wiki Biography, Early Life, Career, Family, Girlfriend, Profession, Education, Earnings

1 week ago
Preoccupano le condizioni di Jack Nicholson che da un anno non esce più di casa

Preoccupano le condizioni di Jack Nicholson che da un anno non esce più di casa

3 weeks ago

Popular News

    Connect with us

    Newsletter

    Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor.
    SUBSCRIBE

    Category

    • Business
    • Entertainment
    • Fashion
    • food
    • Games
    • Gaming
    • Health
    • Italy
    • Lifestyle
    • Movie
    • Music
    • National
    • News
    • Politics
    • Science
    • SPORTS
    • Tech
    • Technology
    • Travel
    • Uncategorized
    • WORLD

    Site Links

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    About Us

    We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

    • About
    • Advertise
    • Careers
    • Contact

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Create New Account!

    Fill the forms below to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In