Lucene search

K
osvGoogleOSV:USN-6793-2
HistoryJun 18, 2024 - 5:47 p.m.

git vulnerability

2024-06-1817:47:28
Google
osv.dev
git
vulnerability
ubuntu
code execution
submodules

9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%

USN-6793-1 fixed vulnerabilities in Git. The CVE-2024-32002 was pending further
investigation. This update fixes the problem.

Original advisory details:

It was discovered that Git incorrectly handled certain submodules.
An attacker could possibly use this issue to execute arbitrary code.
This issue was fixed in Ubuntu 22.04 LTS, Ubuntu 23.10 and Ubuntu 24.04 LTS.
(CVE-2024-32002)

9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%