Upstream information

CVE-2024-38448 at MITRE

Description

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

SUSE Bugzilla entry: 1226420 [IN_PROGRESS]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • global >= 6.6.13-1.1
Patchnames:
openSUSE-Tumbleweed-2024-14123


SUSE Timeline for this CVE

CVE page created: Sun Jun 16 18:00:01 2024
CVE page last modified: Tue Jul 16 16:51:48 2024