Debian dla-3282 : git - security update

critical Nessus Plugin ID 170680

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3282 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3282-1 [email protected] https://www.debian.org/lts/security/ Sylvain Beucler January 26, 2023 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : git Version : 1:2.20.1-2+deb10u7 CVE ID : CVE-2022-23521 CVE-2022-41903 Debian Bug : 1029114

Two vulnerabilities were discovered in Git, a distributed revision control system. An attacker may trigger code execution in specific situations.

CVE-2022-23521

gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute names are huge. These overflows can be triggered via a crafted `.gitattributes` file that may be part of the commit history. Git silently splits lines longer than 2KB when parsing gitattributes from a file, but not when parsing them from the index. Consequentially, the failure mode depends on whether the file exists in the working tree, the index or both. This integer overflow can result in arbitrary heap reads and writes, which may result in remote code execution.

CVE-2022-41903

`git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-subst` gitattribute. When processing the padding operators, there is a integer overflow in `pretty.c::format_and_pad_commit()` where a `size_t` is stored improperly as an `int`, and then added as an offset to a `memcpy()`. This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., `git log --format=...`). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution.

For Debian 10 buster, these problems have been fixed in version 1:2.20.1-2+deb10u7.

We recommend that you upgrade your git packages.

For the detailed security status of git please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/git

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the git packages.

See Also

https://security-tracker.debian.org/tracker/source-package/git

https://security-tracker.debian.org/tracker/CVE-2022-23521

https://security-tracker.debian.org/tracker/CVE-2022-41903

https://packages.debian.org/source/buster/git

Plugin Details

Severity: Critical

ID: 170680

File Name: debian_DLA-3282.nasl

Version: 1.1

Type: local

Agent: unix

Published: 1/26/2023

Updated: 1/22/2025

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-41903

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:git-all, cpe:/o:debian:debian_linux:10.0, p-cpe:/a:debian:debian_linux:git-cvs, p-cpe:/a:debian:debian_linux:git, p-cpe:/a:debian:debian_linux:git-daemon-sysvinit, p-cpe:/a:debian:debian_linux:git-gui, p-cpe:/a:debian:debian_linux:git-mediawiki, p-cpe:/a:debian:debian_linux:git-email, p-cpe:/a:debian:debian_linux:git-daemon-run, p-cpe:/a:debian:debian_linux:git-doc, p-cpe:/a:debian:debian_linux:git-svn, p-cpe:/a:debian:debian_linux:gitk, p-cpe:/a:debian:debian_linux:git-man, p-cpe:/a:debian:debian_linux:gitweb, p-cpe:/a:debian:debian_linux:git-el

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 1/26/2023

Vulnerability Publication Date: 1/17/2023

Reference Information

CVE: CVE-2022-23521, CVE-2022-41903