VDB
GCVE-VVD-MAGEIA-2023-66
GCVE-VVD-MAGEIA-2023-66
Advisory Published
Using a specially-crafted repository, Git can be tricked into using its local
clone optimization even when using a non-local transport. Though Git will
abort local clones whose source $GIT_DIR/objects directory contains symbolic
links, the objects directory itself may still be a symbolic link. These two
may be combined to include arbitrary files based on known paths on the
victim's filesystem within the malicious repository's working copy, allowing
for data exfiltration in a similar manner as CVE-2022-39253 (CVE-2023-22490).
By feeding a crafted input to "git apply", a path outside the working tree can
be overwritten as the user who is running "git apply" (CVE-2023-23946).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | thunar | 0 (affected), 4.18.7-1.mga9 (unaffected) | — |
| Mageia | git | 0 (affected), 2.30.8-1.mga8 (unaffected), 0 (affected), 2.30.8-1.mga8 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.