{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2025-48384: config: quote values containing CR character",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux7els/advisories/2025/clsa-2025_1752655000.json"
      },
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2025:1752655000",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2025:1752655000"
      }
    ],
    "tracking": {
      "current_release_date": "2025-07-16T08:38:13Z",
      "generator": {
        "date": "2025-07-16T08:38:13Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2025:1752655000",
      "initial_release_date": "2025-07-16T08:38:13Z",
      "revision_history": [
        {
          "date": "2025-07-16T08:38:13Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "git: Fix of CVE-2025-48384"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 7",
                "product": {
                  "name": "Oracle Linux 7",
                  "product_id": "Oracle-Linux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-instaweb@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-bzr@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-cvs@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-gui@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-p4@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-email@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                "product": {
                  "name": "git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_id": "git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-hg@1.8.3.1-25.el7_9.tuxcare.els4?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                "product": {
                  "name": "git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_id": "git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-daemon@1.8.3.1-25.el7_9.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                "product": {
                  "name": "git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_id": "git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git-svn@1.8.3.1-25.el7_9.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                "product": {
                  "name": "git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_id": "git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/git@1.8.3.1-25.el7_9.tuxcare.els4?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64"
        },
        "product_reference": "git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64"
        },
        "product_reference": "git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64"
        },
        "product_reference": "git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        },
        "product_reference": "git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
        "relates_to_product_reference": "Oracle-Linux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-48384",
      "notes": [
        {
          "category": "description",
          "text": "No description is available for this CVE.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-48384"
        }
      ],
      "release_date": "2025-07-08T18:23:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "High"
        }
      ]
    },
    {
      "cve": "CVE-2024-32004",
      "cwe": {
        "id": "CWE-114",
        "name": "Process Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-32004"
        }
      ],
      "release_date": "2024-05-14T00:00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "High"
        }
      ]
    },
    {
      "cve": "CVE-2023-23946",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-23946"
        },
        {
          "category": "external",
          "summary": "https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd",
          "url": "https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd"
        },
        {
          "category": "external",
          "summary": "https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh",
          "url": "https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202312-15",
          "url": "https://security.gentoo.org/glsa/202312-15"
        }
      ],
      "release_date": "2023-02-14T20:15:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "High"
        }
      ]
    },
    {
      "cve": "CVE-2021-40330",
      "notes": [
        {
          "category": "description",
          "text": "git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-40330"
        },
        {
          "category": "external",
          "summary": "https://github.com/git/git/commit/a02ea577174ab8ed18f847cf1693f213e0b9c473",
          "url": "https://github.com/git/git/commit/a02ea577174ab8ed18f847cf1693f213e0b9c473"
        },
        {
          "category": "external",
          "summary": "https://github.com/git/git/compare/v2.30.0...v2.30.1",
          "url": "https://github.com/git/git/compare/v2.30.0...v2.30.1"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/10/msg00014.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00014.html"
        }
      ],
      "release_date": "2021-08-31T04:15:00",
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK_ACCESSIBLE",
            "authentication": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "High"
        }
      ]
    },
    {
      "cve": "CVE-2022-39260",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shell` as a login shell in order to be vulnerable to this attack. This problem is patched in versions 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 and users are advised to upgrade to the latest version. Disabling `git shell` access via remote logins is a viable short-term workaround.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
          "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
          "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2022-39260"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2022/Nov/1",
          "url": "http://seclists.org/fulldisclosure/2022/Nov/1"
        },
        {
          "category": "external",
          "summary": "https://github.com/git/git/security/advisories/GHSA-rjr6-wcq6-83p6",
          "url": "https://github.com/git/git/security/advisories/GHSA-rjr6-wcq6-83p6"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/12/msg00025.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00025.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7B6JPKX5CGGLAHXJVQMIZNNEEB72FHD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7B6JPKX5CGGLAHXJVQMIZNNEEB72FHD/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHNO2FB55CPX47BAXMBWUBGWHO6N6ZZH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHNO2FB55CPX47BAXMBWUBGWHO6N6ZZH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKFHE4KVD7EKS5J3KTDFVBEKU3CLXGVV/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKFHE4KVD7EKS5J3KTDFVBEKU3CLXGVV/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202312-15",
          "url": "https://security.gentoo.org/glsa/202312-15"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/kb/HT213496",
          "url": "https://support.apple.com/kb/HT213496"
        }
      ],
      "release_date": "2022-10-19T12:15:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:git-instaweb-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-daemon-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-bzr-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-cvs-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-svn-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-gui-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-p4-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-0:1.8.3.1-25.el7_9.tuxcare.els4.x86_64",
            "Oracle-Linux-7:git-email-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch",
            "Oracle-Linux-7:git-hg-0:1.8.3.1-25.el7_9.tuxcare.els4.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "High"
        }
      ]
    }
  ]
}