Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-25652

Опубликовано: 25 апр. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to git apply --reject, a path outside the working tree can be overwritten with partially controlled contents (corresponding to the rejected hunk(s) from the given patch). A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid using git apply with --reject when applying patches from an untrusted source. Use git apply --stat to inspect a patch before applying; avoid applying one that create a conflict where a link corresponding to the *.rej file exists.

A vulnerability was found in Git. This security flaw occurs when feeding specially crafted input to git apply --reject; a path outside the working tree can be overwritten with partially controlled contents corresponding to the rejected hunk(s) from the given patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12gitOut of support scope
Red Hat Enterprise Linux 6gitOut of support scope
Red Hat Enterprise Linux 7gitFixedRHSA-2023:326323.05.2023
Red Hat Enterprise Linux 8gitFixedRHSA-2023:324622.05.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsgitFixedRHSA-2023:319217.05.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportgitFixedRHSA-2023:338231.05.2023
Red Hat Enterprise Linux 8.4 Extended Update SupportgitFixedRHSA-2023:324322.05.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportgitFixedRHSA-2023:324722.05.2023
Red Hat Enterprise Linux 9gitFixedRHSA-2023:324522.05.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportgitFixedRHSA-2023:324822.05.2023

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2188333git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents

EPSS

Процентиль: 88%
0.0393
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (corresponding to the rejected hunk(s) from the given patch). A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid using `git apply` with `--reject` when applying patches from an untrusted source. Use `git apply --stat` to inspect a patch before applying; avoid applying one that create a conflict where a link corresponding to the `*.rej` file exists.

CVSS3: 7.5
nvd
около 2 лет назад

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (corresponding to the rejected hunk(s) from the given patch). A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid using `git apply` with `--reject` when applying patches from an untrusted source. Use `git apply --stat` to inspect a patch before applying; avoid applying one that create a conflict where a link corresponding to the `*.rej` file exists.

msrc
около 2 лет назад

GitHub: CVE-2023-25652 "git apply --reject" partially-controlled arbitrary file write

CVSS3: 7.5
debian
около 2 лет назад

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2. ...

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость распределенной системы управления версиями Git, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 88%
0.0393
Низкий

7.5 High

CVSS3