Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27614

Опубликовано: 10 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.6

Описание

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

РелизСтатусПримечание
devel

pending

1:2.50.0-1ubuntu3
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

released

1:2.43.0-1ubuntu7.3
oracular

released

1:2.45.2-1ubuntu1.2
plucky

released

1:2.48.1-0ubuntu1.1
upstream

released

2.43.7

Показывать по

EPSS

Процентиль: 4%
0.00022
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
nvd
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

msrc
около 1 месяца назад

MITRE: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability

CVSS3: 8.6
debian
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Gi ...

CVSS3: 8.6
fstec
около 1 месяца назад

Уязвимость команды gitk filename браузера Gitk, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 4%
0.00022
Низкий

8.6 High

CVSS3