Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-all",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-daemon-run",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-daemon-sysvinit",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-email",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-man",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "gitk",
"binary_version": "1:2.34.1-1ubuntu1.15"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.34.1-1ubuntu1.15"
}
]
}{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-all",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-daemon-run",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-daemon-sysvinit",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-email",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-man",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "gitk",
"binary_version": "1:2.43.0-1ubuntu7.3"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.43.0-1ubuntu7.3"
}
]
}{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-all",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-email",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-man",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "gitk",
"binary_version": "1:2.48.1-0ubuntu1.1"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.48.1-0ubuntu1.1"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-all",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-arch",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-core",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-daemon-run",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-daemon-sysvinit",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-el",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-email",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-man",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "gitk",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.7.4-0ubuntu1.10+esm11"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-all",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-daemon-run",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-daemon-sysvinit",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-el",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-email",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-man",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "gitk",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.17.1-1ubuntu0.18+esm4"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "git",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-all",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-cvs",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-daemon-run",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-daemon-sysvinit",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-el",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-email",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-gui",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-man",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-mediawiki",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "git-svn",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "gitk",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
},
{
"binary_name": "gitweb",
"binary_version": "1:2.25.1-1ubuntu3.14+esm3"
}
]
}