Mageia 2018-0445: python-dulwich security update
Summary
Dulwich, when an SSH subprocess is used, allowed remote attackers to
execute arbitrary commands via an ssh URL with an initial dash character
in the hostname (CVE-2017-16228).
References
- https://bugs.mageia.org/show_bug.cgi?id=23346
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16228
Resolution
MGASA-2018-0445 - Updated python-dulwich packages fix security vulnerability
SRPMS
- 6/core/python-dulwich-0.12.0-1.2.mga6