Your message dated Tue, 01 Sep 2026 00:34:10 +0000
with message-id <[email protected]>
and subject line Bug#1145672: fixed in python-git 3.1.61-1
has caused the Debian Bug report #1145672,
regarding python-git: CVE-2026-78675 CVE-2026-78676 CVE-2026-78677 
CVE-2026-78678 CVE-2026-78679
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145672: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145672
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-git
Version: 3.1.50-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for python-git.

CVE-2026-78675[0]:
| GitPython before 3.1.59 fails to disable merge_includes when parsing
| .gitmodules, allowing attackers to disclose local file content by
| including arbitrary file paths via [include] directives. Attackers
| can craft a malicious .gitmodules file with include directives
| pointing to sensitive files; when repo.submodules is accessed,
| GitConfigParser raises MissingSectionHeaderError embedding the
| target file's first line verbatim in the exception message.


CVE-2026-78676[1]:
| GitPython before 3.1.59 fails to safely re-serialize multi-line git-
| config values during write operations, corrupting dormant quoted
| values into injected directives like core.hooksPath. Attackers can
| craft config files with embedded newlines that become live git
| directives after any unrelated GitPython config write, enabling
| arbitrary code execution via hook invocation.


CVE-2026-78677[2]:
| GitPython before 3.1.59 omits --separate-git-dir from
| unsafe_git_clone_options, allowing attackers to create arbitrary git
| directories outside the intended clone destination. Attackers can
| pass a separate_git_dir parameter to Repo.clone_from() or
| Repo.clone() to redirect repository metadata to an attacker-
| controlled filesystem path, enabling arbitrary directory creation
| and potential hook execution.


CVE-2026-78678[3]:
| GitPython versions before 3.1.59 contain an incomplete denylist in
| the unsafe_git_revision_options guard that omits --contents and -S
| options, allowing attackers to read arbitrary files by passing these
| options to Repo.blame(). Attackers can supply revision values like
| --contents=/etc/passwd to leak file contents through the blame
| result returned to the caller.


CVE-2026-78679[4]:
| GitPython before 3.1.59 contains an arbitrary file read
| vulnerability in TagReference.create() where a positional reference
| parameter bypasses the unsafe option guard. Attackers can supply a
| reference value like --file=<path> to read arbitrary files, with
| contents returned in the annotated tag message.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78675
    https://www.cve.org/CVERecord?id=CVE-2026-78675
[1] https://security-tracker.debian.org/tracker/CVE-2026-78676
    https://www.cve.org/CVERecord?id=CVE-2026-78676
[2] https://security-tracker.debian.org/tracker/CVE-2026-78677
    https://www.cve.org/CVERecord?id=CVE-2026-78677
[3] https://security-tracker.debian.org/tracker/CVE-2026-78678
    https://www.cve.org/CVERecord?id=CVE-2026-78678
[4] https://security-tracker.debian.org/tracker/CVE-2026-78679
    https://www.cve.org/CVERecord?id=CVE-2026-78679

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: python-git
Source-Version: 3.1.61-1
Done: Emmanuel Arias <[email protected]>

We believe that the bug you reported is fixed in the latest version of
python-git, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Arias <[email protected]> (supplier of updated python-git package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 31 Aug 2026 21:04:23 -0300
Source: python-git
Architecture: source
Version: 3.1.61-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <[email protected]>
Changed-By: Emmanuel Arias <[email protected]>
Closes: 1143454 1143602 1144344 1144929 1145672
Changes:
 python-git (3.1.61-1) unstable; urgency=high
 .
   * Team upload.
   * New upstream version 3.1.61.
     - Fix CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-67322,
       CVE-2026-69097, CVE-2026-73623, CVE-2026-73624, CVE-2026-73625,
       CVE-2026-73622, CVE-2026-73621, CVE-2026-73619, CVE-2026-73620,
       CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220,
       CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676,
       CVE-2026-78677, CVE-2026-78678, CVE-2026-78679 (Closes: #1143454,
       #1143602, #1144344, #1144929, #1145672)
   * d/tests/control: Add procps to the autopkgtest dependencies.
Checksums-Sha1:
 aee695ae6710f3259917dff61402c23a6cc48ffc 2798 python-git_3.1.61-1.dsc
 a0d48c24a098aa3437ea3524b3095e3d65618c67 1022655 python-git_3.1.61.orig.tar.gz
 5fd8979e50dbe3ce029237490547254d02b7ef6f 7332 python-git_3.1.61-1.debian.tar.xz
 7a3a8741d51ab103eadec2eaa337b7e661ab7f24 8174 
python-git_3.1.61-1_amd64.buildinfo
Checksums-Sha256:
 4dac291bf776a187d1f211780f6e80fe36654fe3f668e8d0177b16a6c6369bb0 2798 
python-git_3.1.61-1.dsc
 e919636aa7a259f9d9ece36037380b70262c7b76e6e93346be13fa0c23cda997 1022655 
python-git_3.1.61.orig.tar.gz
 cf75d0e27114f71cfe5f61582104f9f2a5fb904a46c1f20cff60a67ce38f1062 7332 
python-git_3.1.61-1.debian.tar.xz
 551a06eec67c03aeb2f08ce5812206e98e20af81f0d048db5a61913a34eadc2b 8174 
python-git_3.1.61-1_amd64.buildinfo
Files:
 d9edf33bd778b4cc68fbba90b8a29c14 2798 python optional python-git_3.1.61-1.dsc
 4b2374b7714c18ef801dea5bccb2c5f4 1022655 python optional 
python-git_3.1.61.orig.tar.gz
 ed9f37cb6e1b66441d9ba96a9b2411b5 7332 python optional 
python-git_3.1.61-1.debian.tar.xz
 25928b55bbec50f03910085555ba12dc 8174 python optional 
python-git_3.1.61-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmqWF8sSHGVhbWFudUBk
ZWJpYW4ub3JnAAoJEPqd7F3hHGPx/swQAL1PlG7fMLHGnyCEG6pQLRILniXDQ3xw
aRmH2T2JxYsnKb7JoNBhCqpzqrfUGS98gA/iN+a6ZuNBypZkOPdh/hXH/WY8O3Ma
79SurPprRe+eTAT1J6oXyR+MgwuGt/nIpnD6XQWV4gjkIXurC2pejfBtDqYOTxgj
rmlY9zJOsKFNe1CEK9HkY+JsYiu5AfBm5oUbeDZiU50bpjT8ZJXWqLexMS+hCCHA
hGmnKZEUxPYjcdxbp3li2fy7y2bWvb5Ty85fWFhcMGVDiAgTeAYYa/YSHJO3k0+0
3EK3W07rbZbBjjm8iYAIupeyboocxd6ellWPoBucK4psfybpCqUGsFii0ex1UAwj
uMdrxdbOgWfD+aC+3oRPF9IIguJ63FqV2gNs+fJGKudlTU8X4TRy8D9YcG0/+/a3
EmuZ1HUtOsy+wvd1ol6r0geOwXWleYRNpANK2czzRq8Yb0hjSnn0zw/3YfCifLTr
2gT9Was29RXiVGTgjnQ2UuiaSonaTpBh1Dl0Owo6RPQCNfJDRHGUPWq/gX7h0vWQ
VAJs5fv/VsyhCOaIb76zT2YE+x1X8seW/hnnCH2aFCXKxxCOsI7N/9yEpYvktuic
6TE8y7G6YvDCgHZ0qU27N9vC6CMyTpRKw7IjIL7X65xy5en3WGf6adlL/78NP2Qr
Nmy/1wuP8Zn7
=5GyX
-----END PGP SIGNATURE-----

Attachment: pgp23AFT19yjZ.pgp
Description: PGP signature


--- End Message ---

Reply via email to