USN-7603-1

Source
https://ubuntu.com/security/notices/USN-7603-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7603-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7603-1
Upstream
Related
Published
2025-06-30T04:29:26.999718Z
Modified
2025-07-16T08:55:36.645381Z
Summary
composer vulnerabilities
Details

Thomas Chauchefoin discovered that Composer did not correctly handle certain arguments. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24828, CVE-2023-43655)

Ed Cradock discovered that Composer did not correctly handle the exclusion of certain files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2024-24821)

Martin Haunschmid discovered that Composer did not correctly handle git branch names. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-35241)

Maciej Piechota discovered that Composer did not correctly handle VCS branch names. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-35242)

References

Affected packages

Ubuntu:Pro:16.04:LTS / composer

Package

Name
composer
Purl
pkg:deb/ubuntu/composer@1.0.0~beta2-1ubuntu0.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0~beta2-1ubuntu0.1~esm2

Affected versions

1.*

1.0.0~alpha10+20150602-1
1.0.0~alpha10+20150602-2
1.0.0~alpha11-1
1.0.0~alpha11-1ubuntu1
1.0.0~alpha11-2
1.0.0~alpha11-3
1.0.0~beta1-1ubuntu1
1.0.0~beta2-1
1.0.0~beta2-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "composer",
            "binary_version": "1.0.0~beta2-1ubuntu0.1~esm2"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / composer

Package

Name
composer
Purl
pkg:deb/ubuntu/composer@1.6.3-1ubuntu0.1~esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.3-1ubuntu0.1~esm2

Affected versions

1.*

1.5.1-1
1.5.2-1
1.6.2-1
1.6.3-1
1.6.3-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "composer",
            "binary_version": "1.6.3-1ubuntu0.1~esm2"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / composer

Package

Name
composer
Purl
pkg:deb/ubuntu/composer@1.10.1-1ubuntu0.1~esm2?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-1ubuntu0.1~esm2

Affected versions

1.*

1.9.0-2
1.9.1-1
1.9.2-1
1.9.3-1
1.10.0-1
1.10.1-1
1.10.1-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "composer",
            "binary_version": "1.10.1-1ubuntu0.1~esm2"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / composer

Package

Name
composer
Purl
pkg:deb/ubuntu/composer@2.2.6-2ubuntu4+esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.6-2ubuntu4+esm1

Affected versions

2.*

2.0.9-2ubuntu2
2.0.9-2ubuntu3
2.0.13-1ubuntu1
2.1.12-1ubuntu1
2.2.6-2ubuntu4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "composer",
            "binary_version": "2.2.6-2ubuntu4+esm1"
        }
    ]
}

Ubuntu:Pro:24.04:LTS / composer

Package

Name
composer
Purl
pkg:deb/ubuntu/composer@2.7.1-2ubuntu0.1~esm1?arch=source&distro=esm-apps/noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.1-2ubuntu0.1~esm1

Affected versions

2.*

2.5.8-1
2.6.5-1
2.6.6-1
2.7.1-2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "composer",
            "binary_version": "2.7.1-2ubuntu0.1~esm1"
        }
    ]
}