High
Canonical Ubuntu
Etienne Stalmans discovered that git did not properly validate git submodules files. A remote attacker could possibly use this to craft a git repo that causes arbitrary code execution when โgit clone โrecurse-submodulesโ is used. (CVE-2018-11235)
It was discovered that an integer overflow existed in gitโs pathname sanity checking code when used on NTFS filesystems. An attacker could use this to cause a denial of service or expose sensitive information. (CVE-2018-11233)
Severity is high unless otherwise noted.
OSS users are strongly encouraged to follow one of the mitigations below: