
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (RUSTSEC-2024-0353) affects gitoxide, a pure Rust implementation of Git, specifically on Windows systems. The issue was disclosed on May 22, 2024, and impacts multiple packages including gitoxide, gix-core, gix, gix-index, gix-ref, gix-worktree, and gix-worktree-state. The vulnerability allows malicious repositories to exploit Windows legacy device names during cloning operations (GitHub Advisory).
The vulnerability stems from improper handling of Windows legacy DOS-style device names in two scenarios: First, gix-ref fails to validate reference names before accessing them on disk, leading to device reads. Second, gix-worktree-state incorrectly processes certain path names, resulting in arbitrary data writes to system devices. The issue has been assigned a CVSS v3.1 score of 5.4 (Moderate) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L (GitHub Advisory).
The vulnerability's impact is primarily limited to Windows systems when cloning untrusted repositories. It can cause indefinite blocking through console input manipulation (using CON or CONIN$) or enable the display of arbitrary messages that appear to come from the application (using CON or CONOUT$). Additionally, it may potentially interfere with serial port operations and cause minor availability degradation (GitHub Advisory).
The vulnerability can be exploited by creating a Git repository containing references or filenames that match Windows legacy device names. Two proof-of-concept exploits have been documented: one using a lightweight tag named 'CON' to demonstrate denial of service, and another using a file named 'CON' to display arbitrary messages that appear to come from the application (GitHub Advisory).
Fixed versions have been released for all affected packages: gitoxide (>= 0.36.0), gitoxide-core (>= 0.38.0), gix (>= 0.63.0), gix-index (>= 0.33.0), gix-ref (>= 0.44.0), gix-worktree (>= 0.34.0), and gix-worktree-state (>= 0.11.0). Users should upgrade to these patched versions to mitigate the vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."