安全公告详情

NS-SA-2025-0127

2025-07-25 16:49:52

简介

important: libgit2/librsvg2 security update

严重级别

important

主题

An update for libgit2/librsvg2 is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

libgit2:
librsvg2:


Security Fix(es):
libgit2: A flaw was found in libgit2, a cross-platform, linkable library implementation of Git. This flaw allows an attacker using a specially-crafted payload to `git_revparse_single` and cause the function to enter an infinite loop. This issue potentially causes a denial of service attack in the calling application.(CVE-2024-24575)
libgit2: A flaw was found in libgit2, a cross-platform, linkable library implementation of Git. A specially crafted payload to git_index_add can cause heap corruption that could be leveraged for arbitrary code execution. The attacker must be able to trigger two consecutive calls to git_index_add with a filename that starts with a / character to exploit this vulnerability. To control the heap corruption, the attacker must be able to control the ctime field of the git_index_entry data structure.(CVE-2024-24577)
libgit2: bugfix
librsvg2: A directory traversal vulnerability was discovered in the URL decoder of Librsvg. This issue occurs when xinclude href has special characters; demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element, which can allow an attacker to send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system, affecting the data confidentiality.(CVE-2023-38633)
librsvg2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • libgit2
  • librsvg2

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["libgit2-devel-1.7.2-1.zncgsl7.4.x86_64.rpm","libgit2-1.7.2-1.zncgsl7.4.x86_64.rpm"],"source":"libgit2-1.7.2-1.zncgsl7.4.src.rpm"},{"binary":["librsvg2-2.56.3-1.zncgsl7.4.x86_64.rpm","librsvg2-devel-2.56.3-1.zncgsl7.4.x86_64.rpm","librsvg2-tools-2.56.3-1.zncgsl7.4.x86_64.rpm"],"source":"librsvg2-2.56.3-1.zncgsl7.4.src.rpm"}]}]}

CVE

参考