Bug 1226420 (CVE-2024-38448) - VUL-0: CVE-2024-38448: global: htags may allow code execution via untrusted dbpath
Summary: VUL-0: CVE-2024-38448: global: htags may allow code execution via untrusted d...
Status: IN_PROGRESS
Alias: CVE-2024-38448
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/411058/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-17 08:30 UTC by SMASH SMASH
Modified: 2024-07-18 12:23 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-06-17 08:30:17 UTC
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38448
https://www.cve.org/CVERecord?id=CVE-2024-38448
https://cvs.savannah.gnu.org/viewvc/global/global/htags/htags.c?revision=1.236&view=markup
https://lists.gnu.org/archive/html/bug-global/2024-05/msg00009.html
Comment 1 Andreas Stieger 2024-07-07 07:16:51 UTC
TW bump to 6.6.13: https://build.opensuse.org/request/show/1185956
Leap backport: https://build.opensuse.org/request/show/1185958
Please process.