Lucene search

K
ubuntuUbuntuUSN-5686-4
HistoryMar 28, 2023 - 12:00 a.m.

Git vulnerability

2023-03-2800:00:00
ubuntu.com
34
ubuntu 16.04
git
vulnerabilities
symbolic links
unexpected behavior
esm

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.7%

Releases

  • Ubuntu 16.04 ESM

Packages

  • git - fast, scalable, distributed revision control system

Details

USN-5686-1 fixed several vulnerabilities in Git. This update
provides the corresponding fix for CVE-2022-39253 on Ubuntu 16.04 ESM.

Original advisory details:

Cory Snider discovered that Git incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause an unexpected behaviour.

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchgit< 1:2.7.4-0ubuntu1.10+esm6UNKNOWN
Ubuntu16.04noarchgit< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-all< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-arch< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-core< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-cvs< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-daemon-run< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-daemon-sysvinit< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-doc< 1:2.7.4-0ubuntu1.10UNKNOWN
Ubuntu16.04noarchgit-el< 1:2.7.4-0ubuntu1.10UNKNOWN
Rows per page:
1-10 of 171

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.7%