Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-11534

Опубликовано: 22 июл. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-11534: git security update (IMPORTANT)

[2.43.7-1]

  • update to 2.43.7
  • Resolves: RHEL-102440, RHEL-102454, RHEL-102674, RHEL-102680

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

git

2.43.7-1.el8_10

git-all

2.43.7-1.el8_10

git-core

2.43.7-1.el8_10

git-core-doc

2.43.7-1.el8_10

git-credential-libsecret

2.43.7-1.el8_10

git-daemon

2.43.7-1.el8_10

git-email

2.43.7-1.el8_10

git-gui

2.43.7-1.el8_10

git-instaweb

2.43.7-1.el8_10

git-subtree

2.43.7-1.el8_10

git-svn

2.43.7-1.el8_10

gitk

2.43.7-1.el8_10

gitweb

2.43.7-1.el8_10

perl-Git

2.43.7-1.el8_10

perl-Git-SVN

2.43.7-1.el8_10

Oracle Linux x86_64

git

2.43.7-1.el8_10

git-all

2.43.7-1.el8_10

git-core

2.43.7-1.el8_10

git-core-doc

2.43.7-1.el8_10

git-credential-libsecret

2.43.7-1.el8_10

git-daemon

2.43.7-1.el8_10

git-email

2.43.7-1.el8_10

git-gui

2.43.7-1.el8_10

git-instaweb

2.43.7-1.el8_10

git-subtree

2.43.7-1.el8_10

git-svn

2.43.7-1.el8_10

gitk

2.43.7-1.el8_10

gitweb

2.43.7-1.el8_10

perl-Git

2.43.7-1.el8_10

perl-Git-SVN

2.43.7-1.el8_10

Связанные уязвимости

oracle-oval
19 дней назад

ELSA-2025-11533: git security update (IMPORTANT)

oracle-oval
20 дней назад

ELSA-2025-11462: git security update (IMPORTANT)

CVSS3: 3.6
ubuntu
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 4.3
redhat
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 3.6
nvd
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.