Bug ID 1226420
Summary VUL-0: CVE-2024-38448: global: htags may allow code execution via untrusted dbpath
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/411058/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee sleep_walker@opensuse.org
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC carlos.lopez@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

htags in GNU Global through 6.6.12 allows code execution in situations where
dbpath (aka -d) is untrusted, because shell metacharacters may be used.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38448
https://www.cve.org/CVERecord?id=CVE-2024-38448
https://cvs.savannah.gnu.org/viewvc/global/global/htags/htags.c?revision=1.236&view=markup
https://lists.gnu.org/archive/html/bug-global/2024-05/msg00009.html


You are receiving this mail because: