Oval Definition:oval:org.opensuse.security:def:202229187
Revision Date:2023-06-22Version:1
Title:CVE-2022-29187
Description:

Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-29187
SUSE CVE-2022-29187
SUSE-CU-2022:1651-1
SUSE-CU-2022:1662-1
SUSE-CU-2022:1663-1
SUSE-CU-2022:1664-1
SUSE-CU-2022:1665-1
SUSE-CU-2022:1666-1
SUSE-CU-2022:1668-1
SUSE-CU-2022:1681-1
SUSE-CU-2022:1688-1
SUSE-CU-2022:1690-1
SUSE-CU-2022:1696-1
SUSE-SU-2022:2535-1
SUSE-SU-2022:2537-1
SUSE-SU-2022:2550-1
SUSE-SU-2022:3283-1
SUSE-SU-2022:3494-1
SUSE-SU-2022:3495-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP4
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP2-BCL
SUSE Linux Enterprise Server 15 SP2-LTSS
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND git-core-2.35.3-150300.10.15.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Manager Proxy 4.3 is installed
  • OR SUSE Manager Retail Branch Server 4.3 is installed
  • OR SUSE Manager Server 4.3 is installed
  • AND
  • git-2.35.3-150300.10.15.1 is installed
  • OR git-arch-2.35.3-150300.10.15.1 is installed
  • OR git-cvs-2.35.3-150300.10.15.1 is installed
  • OR git-daemon-2.35.3-150300.10.15.1 is installed
  • OR git-doc-2.35.3-150300.10.15.1 is installed
  • OR git-email-2.35.3-150300.10.15.1 is installed
  • OR git-gui-2.35.3-150300.10.15.1 is installed
  • OR git-svn-2.35.3-150300.10.15.1 is installed
  • OR git-web-2.35.3-150300.10.15.1 is installed
  • OR gitk-2.35.3-150300.10.15.1 is installed
  • OR perl-Git-2.35.3-150300.10.15.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS is installed
  • AND
  • git-2.26.2-150000.41.1 is installed
  • OR git-arch-2.26.2-150000.41.1 is installed
  • OR git-core-2.26.2-150000.41.1 is installed
  • OR git-cvs-2.26.2-150000.41.1 is installed
  • OR git-daemon-2.26.2-150000.41.1 is installed
  • OR git-doc-2.26.2-150000.41.1 is installed
  • OR git-email-2.26.2-150000.41.1 is installed
  • OR git-gui-2.26.2-150000.41.1 is installed
  • OR git-svn-2.26.2-150000.41.1 is installed
  • OR git-web-2.26.2-150000.41.1 is installed
  • OR gitk-2.26.2-150000.41.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 15 SP2-LTSS is installed
  • AND
  • git-2.26.2-150000.41.1 is installed
  • OR git-arch-2.26.2-150000.41.1 is installed
  • OR git-core-2.26.2-150000.41.1 is installed
  • OR git-cvs-2.26.2-150000.41.1 is installed
  • OR git-daemon-2.26.2-150000.41.1 is installed
  • OR git-doc-2.26.2-150000.41.1 is installed
  • OR git-email-2.26.2-150000.41.1 is installed
  • OR git-gui-2.26.2-150000.41.1 is installed
  • OR git-svn-2.26.2-150000.41.1 is installed
  • OR git-web-2.26.2-150000.41.1 is installed
  • OR gitk-2.26.2-150000.41.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 15 SP2-BCL is installed
  • AND
  • git-2.26.2-150000.41.1 is installed
  • OR git-arch-2.26.2-150000.41.1 is installed
  • OR git-core-2.26.2-150000.41.1 is installed
  • OR git-cvs-2.26.2-150000.41.1 is installed
  • OR git-daemon-2.26.2-150000.41.1 is installed
  • OR git-doc-2.26.2-150000.41.1 is installed
  • OR git-email-2.26.2-150000.41.1 is installed
  • OR git-gui-2.26.2-150000.41.1 is installed
  • OR git-svn-2.26.2-150000.41.1 is installed
  • OR git-web-2.26.2-150000.41.1 is installed
  • OR gitk-2.26.2-150000.41.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • AND
  • git-2.26.2-150000.41.1 is installed
  • OR git-arch-2.26.2-150000.41.1 is installed
  • OR git-core-2.26.2-150000.41.1 is installed
  • OR git-cvs-2.26.2-150000.41.1 is installed
  • OR git-daemon-2.26.2-150000.41.1 is installed
  • OR git-doc-2.26.2-150000.41.1 is installed
  • OR git-email-2.26.2-150000.41.1 is installed
  • OR git-gui-2.26.2-150000.41.1 is installed
  • OR git-svn-2.26.2-150000.41.1 is installed
  • OR git-web-2.26.2-150000.41.1 is installed
  • OR gitk-2.26.2-150000.41.1 is installed
  • OR libgit2-26 is affected
  • OR libgit2-28 is affected
  • OR libgit2-devel is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • OR SUSE Linux Enterprise Software Development Kit 12 SP5 is installed
  • AND
  • git-2.26.2-27.57.1 is installed
  • OR git-arch-2.26.2-27.57.1 is installed
  • OR git-core-2.26.2-27.57.1 is installed
  • OR git-cvs-2.26.2-27.57.1 is installed
  • OR git-daemon-2.26.2-27.57.1 is installed
  • OR git-doc-2.26.2-27.57.1 is installed
  • OR git-email-2.26.2-27.57.1 is installed
  • OR git-gui-2.26.2-27.57.1 is installed
  • OR git-svn-2.26.2-27.57.1 is installed
  • OR git-web-2.26.2-27.57.1 is installed
  • OR gitk-2.26.2-27.57.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND
  • git-2.26.2-27.57.1 is installed
  • OR git-core-2.26.2-27.57.1 is installed
  • OR git-cvs-2.26.2-27.57.1 is installed
  • OR git-daemon-2.26.2-27.57.1 is installed
  • OR git-email-2.26.2-27.57.1 is installed
  • OR git-gui-2.26.2-27.57.1 is installed
  • OR git-svn-2.26.2-27.57.1 is installed
  • OR git-web-2.26.2-27.57.1 is installed
  • OR gitk-2.26.2-27.57.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • git-2.26.2-27.57.1 is installed
  • OR git-core-2.26.2-27.57.1 is installed
  • OR git-cvs-2.26.2-27.57.1 is installed
  • OR git-daemon-2.26.2-27.57.1 is installed
  • OR git-email-2.26.2-27.57.1 is installed
  • OR git-gui-2.26.2-27.57.1 is installed
  • OR git-svn-2.26.2-27.57.1 is installed
  • OR git-web-2.26.2-27.57.1 is installed
  • OR gitk-2.26.2-27.57.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND
  • git-2.26.2-27.57.1 is installed
  • OR git-core-2.26.2-27.57.1 is installed
  • OR git-cvs-2.26.2-27.57.1 is installed
  • OR git-daemon-2.26.2-27.57.1 is installed
  • OR git-email-2.26.2-27.57.1 is installed
  • OR git-gui-2.26.2-27.57.1 is installed
  • OR git-svn-2.26.2-27.57.1 is installed
  • OR git-web-2.26.2-27.57.1 is installed
  • OR gitk-2.26.2-27.57.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND
  • git-2.26.2-27.57.1 is installed
  • OR git-core-2.26.2-27.57.1 is installed
  • OR git-cvs-2.26.2-27.57.1 is installed
  • OR git-daemon-2.26.2-27.57.1 is installed
  • OR git-email-2.26.2-27.57.1 is installed
  • OR git-gui-2.26.2-27.57.1 is installed
  • OR git-svn-2.26.2-27.57.1 is installed
  • OR git-web-2.26.2-27.57.1 is installed
  • OR gitk-2.26.2-27.57.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND git-core-2.35.3-150300.10.27.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • git-2.35.3-150300.10.27.1 is installed
  • OR git-arch-2.35.3-150300.10.27.1 is installed
  • OR git-cvs-2.35.3-150300.10.27.1 is installed
  • OR git-daemon-2.35.3-150300.10.27.1 is installed
  • OR git-doc-2.35.3-150300.10.27.1 is installed
  • OR git-email-2.35.3-150300.10.27.1 is installed
  • OR git-gui-2.35.3-150300.10.27.1 is installed
  • OR git-svn-2.35.3-150300.10.27.1 is installed
  • OR git-web-2.35.3-150300.10.27.1 is installed
  • OR gitk-2.35.3-150300.10.27.1 is installed
  • OR libgit2-1_3-1.3.0-150400.3.6.1 is installed
  • OR libgit2-devel-1.3.0-150400.3.6.1 is installed
  • OR perl-Git-2.35.3-150300.10.27.1 is installed
  • BACK