Debian Rust-Gix-Worktree vulnerabilities
2 known vulnerabilities affecting debian/rust-gix-worktree.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-35186HIGHCVSS 8.8fixed in rust-gix-fs 0.11.3-1 (forky)2024
CVE-2024-35186 [HIGH] CVE-2024-35186: rust-gix-fs - gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-st...
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality, integrity, and availability, but creating files
debian
CVE-2024-35197LOWCVSS 5.42024
CVE-2024-35197 [MEDIUM] CVE-2024-35197: rust-gix-index - gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that cl...
gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary message that appear to have come from t
debian