FreeBSD : git -- Arbitrary command execution on case-insensitive filesystems (1d567278-87a5-11e4-879c-000c292ee6b8)

This script is Copyright (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

The Git Project reports :

When using a case-insensitive filesystem an attacker can craft a
malicious Git tree that will cause Git to overwrite its own
.git/config file when cloning or checking out a repository, leading to
arbitrary command execution in the client machine. If you are a
hosting service whose users may fetch from your service to Windows or
Mac OS X machines, you are strongly encouraged to update to protect
such users who use existing versions of Git.

See also :

https://github.com/blog/1938-git-client-vulnerability-announced
http://article.gmane.org/gmane.linux.kernel/1853266
http://www.nessus.org/u?1014c2ed

Solution :

Update the affected package.

Risk factor :

High

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 80148 ()

Bugtraq ID:

CVE ID: CVE-2014-9390

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now