Логотип exploitDog
bind:CVE-2024-45405
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45405

Количество 5

Количество 5

ubuntu логотип

CVE-2024-45405

больше 1 года назад

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution. Version 0.10.11 contains a patch for the issue. In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation. Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths. Instead, to cover the occasional case that `git` outputs a quoted path, they attempt to parse the path by stripping the quotation marks. The problem is that, when a path is quoted, it may chang...

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2024-45405

больше 1 года назад

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution. Version 0.10.11 contains a patch for the issue. In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation. Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths. Instead, to cover the occasional case that `git` outputs a quoted path, they attempt to parse the path by stripping the quotation marks. The problem is that, when a path is quoted, it may change

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2024-45405

больше 1 года назад

`gix-path` is a crate of the `gitoxide` project (an implementation of ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3748-1

больше 1 года назад

Security update for cargo-c

EPSS: Низкий
github логотип

GHSA-m8rp-vv92-46c7

больше 1 года назад

gix-path improperly resolves configuration path reported by Git

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-45405

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution. Version 0.10.11 contains a patch for the issue. In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation. Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths. Instead, to cover the occasional case that `git` outputs a quoted path, they attempt to parse the path by stripping the quotation marks. The problem is that, when a path is quoted, it may chang...

CVSS3: 6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45405

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution. Version 0.10.11 contains a patch for the issue. In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation. Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths. Instead, to cover the occasional case that `git` outputs a quoted path, they attempt to parse the path by stripping the quotation marks. The problem is that, when a path is quoted, it may change

CVSS3: 6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45405

`gix-path` is a crate of the `gitoxide` project (an implementation of ...

CVSS3: 6
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3748-1

Security update for cargo-c

0%
Низкий
больше 1 года назад
github логотип
GHSA-m8rp-vv92-46c7

gix-path improperly resolves configuration path reported by Git

CVSS3: 6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу