Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-46334

Опубликовано: 10 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.6

Описание

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

РелизСтатусПримечание
devel

not-affected

Windows only
esm-infra/bionic

not-affected

Windows only
esm-infra/focal

not-affected

Windows only
esm-infra/xenial

not-affected

Windows only
jammy

not-affected

Windows only
noble

not-affected

Windows only
oracular

not-affected

Windows only
plucky

not-affected

Windows only
upstream

pending

2.43.7

Показывать по

Ссылки на источники

EPSS

Процентиль: 12%
0.0004
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
4 месяца назад

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

msrc
4 месяца назад

GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability

CVSS3: 8.6
debian
4 месяца назад

Git GUI allows you to use the Git source control management tools via ...

CVSS3: 8.6
fstec
4 месяца назад

Уязвимость графического инструмента Git GUI распределенной системы контроля версий Git средства разработки программного обеспечения Microsoft Visual Studio, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 12%
0.0004
Низкий

8.6 High

CVSS3