4fd910d Fix ADC security issue

Authored and Committed by lkundrak 13 years ago
    Fix ADC security issue
    
    Dylan Alex Simon discovered and reported a directory traversal flaw in
    the way Gitolite restricted access to admin defined commands ("ADC"). An
    authenticated attacker could execute arbitrary code with privileges of
    Gitolite server user using specially crafted command name.
    
    The flaw does not affect default Gitolite installations. Users who have
    enabled ADC in their configurations are advised to install the updated
    package which includes a fix to resolve the issue.
    
        
file added
+20
file modified
+6 -1