Upstream information

CVE-2024-38448 at MITRE

Description

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

SUSE Bugzilla entry: 1226420 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP5
  • global >= 6.6.9-bp155.2.3.1
Patchnames:
openSUSE-2024-210
SUSE Package Hub 15 SP6
  • global >= 6.6.9-bp156.3.3.1
Patchnames:
openSUSE-2024-210
openSUSE Leap 15.5
  • global >= 6.6.9-bp155.2.3.1
Patchnames:
openSUSE-2024-210
openSUSE Leap 15.6
  • global >= 6.6.9-bp156.3.3.1
Patchnames:
openSUSE-2024-210
openSUSE Tumbleweed
  • global >= 6.6.13-1.1
Patchnames:
openSUSE-Tumbleweed-2024-14123


SUSE Timeline for this CVE

CVE page created: Sun Jun 16 18:00:01 2024
CVE page last modified: Wed Nov 27 12:20:17 2024