Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-29007
HistoryApr 25, 2023 - 12:00 a.m.

CVE-2023-29007

2023-04-2500:00:00
ubuntu.com
ubuntu.com
18
git
vulnerability
remote code execution
.gitmodules
configuration
fix
workaround
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

75.0%

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7,
2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a
specially crafted .gitmodules file with submodule URLs that are longer
than 1024 characters can used to exploit a bug in
config.c::git_config_copy_or_rename_section_in_file(). This bug can be
used to inject arbitrary configuration into a user’s $GIT_DIR/config when
attempting to remove the configuration section associated with that
submodule. When the attacker injects configuration values which specify
executables to run (such as core.pager, core.editor, core.sshCommand,
etc.) this can lead to a remote code execution. A fix A fix is available in
versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7,
2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid running git submodule deinit on untrusted repositories or without prior inspection of any
submodule sections in $GIT_DIR/config.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchgit< 1:2.17.1-1ubuntu0.18UNKNOWN
ubuntu20.04noarchgit< 1:2.25.1-1ubuntu3.11UNKNOWN
ubuntu22.04noarchgit< 1:2.34.1-1ubuntu1.9UNKNOWN
ubuntu22.10noarchgit< 1:2.37.2-1ubuntu1.5UNKNOWN
ubuntu23.04noarchgit< 1:2.39.2-1ubuntu1.1UNKNOWN
ubuntu16.04noarchgit< 1:2.7.4-0ubuntu1.10+esm7UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

75.0%