Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Pure VPN - Up to 27 Months
vgp
Updated:
Friday at 8:10 AM
එක පැකේජ් එකයි මාසෙටම Unlimited Internet. තාමත් DATA CARD දාන්න සල්ලි වියදම් කරනවද? අඩුම මිලට අපෙන්.
sayuru bandara
Updated:
Tuesday at 12:30 PM
Ad icon
ඉන්ටර්නෙට් එකෙන් හරියටම සල්ලි හොයන්න සහ Success වෙන්න කැමතිද? 🚀 (E-Money & Success Stories)
siri sumana
Updated:
May 30, 2026
Gemini AI PRO 18 months Offer
Hawaka
Updated:
May 27, 2026
Ad icon
koko account
DasunEranga
Updated:
May 27, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
Computers & Internet
News & Discussion
Git Users Urged to Update Software to Prevent Remote Code Execution Attacks
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="EdNygma" data-source="post: 28525589" data-attributes="member: 560495"><p><img src="https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEg4BrplWeBfjJku4m0yuXYxF_qIAbkShAXoh0PPPiOyLsYY5TLK8kMFnaY6Is9Ewn54ZJArOXJElQFZtDv9INsTxgxTtKc6EF2P0m9BpCcddg26dMtyvscfNlN-YrPWNeOrh37ObG7waIIH5mWvbg8xZ_2SCavCRDJDD2Af2uV0AB6THMXaaPwnwWxP/s728-rj-e365/git.png" alt="" class="fr-fic fr-dii fr-draggable " style="width: 442px" /></p><p></p><p>The maintainers of the <a href="https://git-scm.com/" target="_blank">Git</a> source code version control system have released updates to remediate two critical vulnerabilities that could be exploited by a malicious actor to achieve remote code execution.</p><p></p><p>The flaws, tracked as <a href="https://github.com/git/git/security/advisories/GHSA-c738-c5qq-xg89" target="_blank"><strong>CVE-2022-23521</strong></a> and <a href="https://github.com/git/git/security/advisories/GHSA-475x-2q3q-hvwq" target="_blank"><strong>CVE-2022-41903</strong></a>, impacts the following versions of Git: v2.30.6, v2.31.5, v2.32.4, v2.33.5, v2.34.5, v2.35.5, v2.36.3, v2.37.4, v2.38.2, and v2.39.0.</p><p></p><p>Patched versions include v2.30.7, v2.31.6, v2.32.5, v2.33.6, v2.34.6, v2.35.6, v2.36.4, v2.37.5, v2.38.3, and v2.39.1. X41 D-Sec security researchers Markus Vervier and Eric Sesterhenn as well as GitLab's Joern Schneeweisz have been credited with reporting the bugs.</p><p></p><p>"The most severe issue discovered allows an attacker to trigger a heap-based memory corruption during clone or pull operations, which might result in code execution," the German cybersecurity company <a href="https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/" target="_blank">said</a> of CVE-2022-23521.</p><p></p><p>CVE-2022-41903, also a critical vulnerability, is triggered during an archive operation, leading to code execution by way of an integer overflow flaw that arises when formatting the commit logs.</p><p></p><p>"Additionally, a huge number of integer related issues was identified which may lead to denial-of-service situations, out-of-bound reads or simply badly handled corner cases on large input," X41 D-Sec noted.</p><p></p><p>While there are no workarounds for CVE-2022-23521, Git is recommending that users disable "git archive" in untrusted repositories as a mitigation for CVE-2022-41903 in scenarios where updating to the latest version is not an option.</p><p></p><p>GitLab, in a coordinated advisory, <a href="https://about.gitlab.com/releases/2023/01/17/critical-security-release-gitlab-15-7-5-released/" target="_blank">said</a> it has released versions 15.7.5, 15.6.6, and 15.5.9 for GitLab Community Edition (CE) and Enterprise Edition (EE) to address the shortcomings, urging customers to apply the fixes with immediate effect.</p><p></p><p></p><p>Source: <a href="https://thehackernews.com/2023/01/git-users-urged-to-update-software-to.html" target="_blank">https://thehackernews.com/2023/01/git-users-urged-to-update-software-to.html</a></p></blockquote><p></p>
[QUOTE="EdNygma, post: 28525589, member: 560495"] [IMG width="442px"]https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEg4BrplWeBfjJku4m0yuXYxF_qIAbkShAXoh0PPPiOyLsYY5TLK8kMFnaY6Is9Ewn54ZJArOXJElQFZtDv9INsTxgxTtKc6EF2P0m9BpCcddg26dMtyvscfNlN-YrPWNeOrh37ObG7waIIH5mWvbg8xZ_2SCavCRDJDD2Af2uV0AB6THMXaaPwnwWxP/s728-rj-e365/git.png[/IMG] The maintainers of the [URL='https://git-scm.com/']Git[/URL] source code version control system have released updates to remediate two critical vulnerabilities that could be exploited by a malicious actor to achieve remote code execution. The flaws, tracked as [URL='https://github.com/git/git/security/advisories/GHSA-c738-c5qq-xg89'][B]CVE-2022-23521[/B][/URL] and [URL='https://github.com/git/git/security/advisories/GHSA-475x-2q3q-hvwq'][B]CVE-2022-41903[/B][/URL], impacts the following versions of Git: v2.30.6, v2.31.5, v2.32.4, v2.33.5, v2.34.5, v2.35.5, v2.36.3, v2.37.4, v2.38.2, and v2.39.0. Patched versions include v2.30.7, v2.31.6, v2.32.5, v2.33.6, v2.34.6, v2.35.6, v2.36.4, v2.37.5, v2.38.3, and v2.39.1. X41 D-Sec security researchers Markus Vervier and Eric Sesterhenn as well as GitLab's Joern Schneeweisz have been credited with reporting the bugs. "The most severe issue discovered allows an attacker to trigger a heap-based memory corruption during clone or pull operations, which might result in code execution," the German cybersecurity company [URL='https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/']said[/URL] of CVE-2022-23521. CVE-2022-41903, also a critical vulnerability, is triggered during an archive operation, leading to code execution by way of an integer overflow flaw that arises when formatting the commit logs. "Additionally, a huge number of integer related issues was identified which may lead to denial-of-service situations, out-of-bound reads or simply badly handled corner cases on large input," X41 D-Sec noted. While there are no workarounds for CVE-2022-23521, Git is recommending that users disable "git archive" in untrusted repositories as a mitigation for CVE-2022-41903 in scenarios where updating to the latest version is not an option. GitLab, in a coordinated advisory, [URL='https://about.gitlab.com/releases/2023/01/17/critical-security-release-gitlab-15-7-5-released/']said[/URL] it has released versions 15.7.5, 15.6.6, and 15.5.9 for GitLab Community Edition (CE) and Enterprise Edition (EE) to address the shortcomings, urging customers to apply the fixes with immediate effect. Source: [URL]https://thehackernews.com/2023/01/git-users-urged-to-update-software-to.html[/URL] [/QUOTE]
Insert quotes…
Verification
Hath warak paha keeyada? (hatha wadikireema paha)
Post reply
Top
Bottom