REDHAT-BUG-2188337: Low severity Git Git vulnerability
CVE-2023-25815: When Git is compiled with runtime prefix support and runs without translated messages, it still used the gettext machinery to display messages, which subsequently potentially looked for translated messages in unexpected places. This allowed for malicious placement of crafted messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2188337?
The severity of REDHAT-BUG-2188337 is classified based on the potential for malicious manipulation of messages within Git.
How do I fix REDHAT-BUG-2188337?
To fix REDHAT-BUG-2188337, ensure that you update Git to the latest version that addresses this vulnerability.
What are the risks associated with REDHAT-BUG-2188337?
The risks associated with REDHAT-BUG-2188337 include the potential for display of misleading messages that can be exploited by attackers.
What versions of Git are affected by REDHAT-BUG-2188337?
Git versions compiled with runtime prefix support are affected by REDHAT-BUG-2188337.
Is there a workaround for REDHAT-BUG-2188337?
A workaround for REDHAT-BUG-2188337 may include disabling the gettext functionality or ensuring that message translations are securely managed.