Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.856187
Categoría:openSUSE Local Security Checks
Título:openSUSE Security Advisory (SUSE-SU-2024:1807-1)
Resumen:The remote host is missing an update for the 'git' package(s) announced via the SUSE-SU-2024:1807-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'git' package(s) announced via the SUSE-SU-2024:1807-1 advisory.

Vulnerability Insight:
This update for git fixes the following issues:

- CVE-2024-32002: Fixed recursive clones on case-insensitive filesystems that support symbolic links are susceptible to case confusion (bsc#1224168).
- CVE-2024-32004: Fixed arbitrary code execution during local clones (bsc#1224170).
- CVE-2024-32020: Fixed file overwriting vulnerability during local clones (bsc#1224171).
- CVE-2024-32021: Fixed git may create hardlinks to arbitrary user-readable files (bsc#1224172).
- CVE-2024-32465: Fixed arbitrary code execution during clone operations (bsc#1224173).

Affected Software/OS:
'git' package(s) on openSUSE Leap 15.5.

Solution:
Please install the updated package(s).

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-32002
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4CK4IYTXEOBZTEM5K3T6LWOIZ3S44AR/
https://git-scm.com/docs/git-clone#Documentation/git-clone.txt---recurse-submodulesltpathspecgt
https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks
https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d
https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv
http://www.openwall.com/lists/oss-security/2024/05/14/2
Common Vulnerability Exposure (CVE) ID: CVE-2024-32004
https://git-scm.com/docs/git-clone
https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8
https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389
Common Vulnerability Exposure (CVE) ID: CVE-2024-32020
https://github.com/git/git/commit/1204e1a824c34071019fe106348eaa6d88f9528d
https://github.com/git/git/commit/9e65df5eab274bf74c7b570107aacd1303a1e703
https://github.com/git/git/security/advisories/GHSA-5rfh-556j-fhgj
Common Vulnerability Exposure (CVE) ID: CVE-2024-32021
https://github.com/git/git/security/advisories/GHSA-mvxm-9j2h-qjx7
Common Vulnerability Exposure (CVE) ID: CVE-2024-32465
https://git-scm.com/docs/git#_security
https://github.com/git/git/commit/7b70e9efb18c2cc3f219af399bd384c5801ba1d7
https://github.com/git/git/security/advisories/GHSA-vm9j-46j9-qvq4
CopyrightCopyright (C) 2024 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.