gitweb security hole (CVE-2010-3906)

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: pgsql-www(at)postgreSQL(dot)org
Subject: gitweb security hole (CVE-2010-3906)
Date: 2011-01-03 20:07:47
Message-ID: 23994.1294085267@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

Just read this on the Fedora update feed:

> Update to 1.7.3.4 release which fixes various issues, notably:
>
> * cross-site scripting (XSS) flaw was found in the web interface of Git distributed revision control system. A remote attacker could use this flaw to execute arbitrary HTML or scripting code by providing a certain URL with specially-crafted values of f and fp variables. (CVE-2010-3906)

Not sure if that impacts the PG gitweb server, but seems like it merits
prompt investigation.

regards, tom lane

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Magnus Hagander 2011-01-03 20:11:41 Re: gitweb security hole (CVE-2010-3906)
Previous Message char101 2010-12-29 13:01:37 Re: missing manual