Логотип exploitDog
bind: "CVE-2025-27613"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-27613"

Количество 15

Количество 15

ubuntu логотип

CVE-2025-27613

6 месяцев назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 3.6
EPSS: Низкий
redhat логотип

CVE-2025-27613

6 месяцев назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-27613

6 месяцев назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 3.6
EPSS: Низкий
msrc логотип

CVE-2025-27613

6 месяцев назад

GitHub: CVE-2025-27613 Gitk Arguments Vulnerability

EPSS: Низкий
debian логотип

CVE-2025-27613

6 месяцев назад

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when ...

CVSS3: 3.6
EPSS: Низкий
fstec логотип

BDU:2025-09364

6 месяцев назад

Уязвимость функций Support per-file encoding() и Show origin of this line() браузера Gitk, позволяющая нарушителю получить несанкционированный доступ на создание и удаление файлов пользователя

CVSS3: 3.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03022-1

4 месяца назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03037-1

4 месяца назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03012-1

4 месяца назад

security update for git, git-lfs, obs-scm-bridge, python-PyYAML

EPSS: Низкий
rocky логотип

RLSA-2025:11534

5 месяцев назад

Important: git security update

EPSS: Низкий
rocky логотип

RLSA-2025:11462

3 месяца назад

Important: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11534

5 месяцев назад

ELSA-2025-11534: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11533

5 месяцев назад

ELSA-2025-11533: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11462

5 месяцев назад

ELSA-2025-11462: git security update (IMPORTANT)

EPSS: Низкий
redos логотип

ROS-20250807-04

5 месяцев назад

Множественные уязвимости git

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-27613

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 3.6
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-27613

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-27613

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS3: 3.6
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-27613

GitHub: CVE-2025-27613 Gitk Arguments Vulnerability

0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-27613

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when ...

CVSS3: 3.6
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-09364

Уязвимость функций Support per-file encoding() и Show origin of this line() браузера Gitk, позволяющая нарушителю получить несанкционированный доступ на создание и удаление файлов пользователя

CVSS3: 3.6
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03022-1

Security update for git

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03037-1

Security update for git

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03012-1

security update for git, git-lfs, obs-scm-bridge, python-PyYAML

4 месяца назад
rocky логотип
RLSA-2025:11534

Important: git security update

5 месяцев назад
rocky логотип
RLSA-2025:11462

Important: git security update

3 месяца назад
oracle-oval логотип
ELSA-2025-11534

ELSA-2025-11534: git security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-11533

ELSA-2025-11533: git security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-11462

ELSA-2025-11462: git security update (IMPORTANT)

5 месяцев назад
redos логотип
ROS-20250807-04

Множественные уязвимости git

CVSS3: 8.6
5 месяцев назад

Уязвимостей на страницу