ALPINE-CVE-2023-25652

Source
https://security.alpinelinux.org/vuln/CVE-2023-25652
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2023-25652
Upstream
Published
2023-04-25T20:15:09.933Z
Modified
2026-08-07T06:18:01.485091231Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to git apply --reject, a path outside the working tree can be overwritten with partially controlled contents (corresponding to the rejected hunk(s) from the given patch). A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid using git apply with --reject when applying patches from an untrusted source. Use git apply --stat to inspect a patch before applying; avoid applying one that create a conflict where a link corresponding to the *.rej file exists.

References

Affected packages

Alpine:v3.14
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.32.7-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.15
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.34.8-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.16
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.36.6-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.17
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.38.5-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.18
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.19
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.20
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.21
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.22
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.23
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"
Alpine:v3.24
git

Package

Name
git
Purl
pkg:apk/alpine/git?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.31.0
Fixed
2.40.1-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2023-25652.json"