Logo
vulnerabilityCVE-2025-27613
Name
CVE-2025-27613
Source
NVD ( link)Debian ( link)
Description
Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
git
Patched

Vulnerability Ratings#


3.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.48.2
Not Affected
buildroot
master
2.54.0
Not Affected
openwrt
master
2.50.1-r1
Not Affected
openwrt
openwrt-25.12
2.50.1-r1
Not Affected
yocto
master
2.54.0
Not Affected
yocto
scarthgap
2.44.4
Not Affected

Resolved with patches#


git (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
d61cfed2c23705fbeb9c0d08f59e75ee08738950 Merge: 664d4fa692 311d9ada3a
CVE-2025-27613
CVE-2025-27614
CVE-2025-46334
CVE-2025-46835