CVE-2018-16976

NameCVE-2018-16976
DescriptionGitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs908699

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gitolite3 (PTS)buster3.6.11-2fixed
sid, trixie, bookworm, bullseye3.6.12-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gitolitesource(unstable)(unfixed)
gitolite3source(unstable)3.6.9-1908699

Notes

[stretch] - gitolite3 <no-dsa> (Minor issue)
[jessie] - gitolite3 <no-dsa> (Minor issue)
https://groups.google.com/forum/#!topic/gitolite-announce/WrwDTYdbfRg
https://github.com/sitaramc/gitolite/commit/dc13dfca8fdae5634bb0865f7e9822d2a268ed59

Search for package or bug name: Reporting problems