Vulnerability Description
Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lars Hjemli | Cgit | <= 0.9.0.3 |
References
- http://git.zx2c4.com/cgit/commit/?id=7ea35f9f8ecf61ab42be9947aae1176ab6e089bd
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00004.html
- http://secunia.com/advisories/50734Vendor Advisory
- http://secunia.com/advisories/51167Vendor Advisory
- http://secunia.com/advisories/51222
- http://www.openwall.com/lists/oss-security/2012/10/28/1
- http://www.openwall.com/lists/oss-security/2012/10/28/2
- http://www.securityfocus.com/bid/56315
- https://bugzilla.redhat.com/show_bug.cgi?id=870713
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79665
- http://git.zx2c4.com/cgit/commit/?id=7ea35f9f8ecf61ab42be9947aae1176ab6e089bd
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00021.html
FAQ
What is CVE-2012-4548?
CVE-2012-4548 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in arg...
How severe is CVE-2012-4548?
CVE-2012-4548 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4548?
Check the references section above for vendor advisories and patch information. Affected products include: Lars Hjemli Cgit.