Oval Definition:oval:org.opensuse.security:def:202329007
Revision Date:2023-06-22Version:1
Title:CVE-2023-29007
Description:

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary configuration into a user's `$GIT_DIR/config` when attempting to remove the configuration section associated with that submodule. When the attacker injects configuration values which specify executables to run (such as `core.pager`, `core.editor`, `core.sshCommand`, etc.) this can lead to a remote code execution. A fix A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid running `git submodule deinit` on untrusted repositories or without prior inspection of any submodule sections in `$GIT_DIR/config`.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2023-29007
SUSE CVE-2023-29007
SUSE-CU-2023:1288-1
SUSE-CU-2023:1289-1
SUSE-CU-2023:1290-1
SUSE-CU-2023:1291-1
SUSE-CU-2023:1292-1
SUSE-CU-2023:1293-1
SUSE-CU-2023:1294-1
SUSE-CU-2023:1295-1
SUSE-CU-2023:1296-1
SUSE-CU-2023:1301-1
SUSE-SU-2023:2038-1
SUSE-SU-2023:2038-2
SUSE-SU-2023:2062-1
SUSE-SU-2023:2081-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND git-core-2.35.3-150300.10.27.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • git-2.35.3-150300.10.27.1 is installed
  • OR git-arch-2.35.3-150300.10.27.1 is installed
  • OR git-cvs-2.35.3-150300.10.27.1 is installed
  • OR git-daemon-2.35.3-150300.10.27.1 is installed
  • OR git-doc-2.35.3-150300.10.27.1 is installed
  • OR git-email-2.35.3-150300.10.27.1 is installed
  • OR git-gui-2.35.3-150300.10.27.1 is installed
  • OR git-svn-2.35.3-150300.10.27.1 is installed
  • OR git-web-2.35.3-150300.10.27.1 is installed
  • OR gitk-2.35.3-150300.10.27.1 is installed
  • OR perl-Git-2.35.3-150300.10.27.1 is installed
  • OR libgit2-1_3 is not affected
  • OR libgit2-devel is not affected
  • BACK