Fedora 42 update for helix, rust-cargo, rust-cargo-deny, rust-cargo-lock, rust-cargo_metadata, rust-cargo_metadata0.18, rust-dua-cli, rust-gengo, rust-gix, rust-gix-actor, rust-gix-archive, rust-gix-attributes, rust-gix-bitmap, rust-gix-chunk, rust-gix-co



Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2024-39338
CVE-2024-56201
CWE-ID CWE-918
CWE-254
Exploitation vector Network
Public exploit N/A
Vulnerable software
Fedora
Operating systems & Components / Operating system

stgit
Operating systems & Components / Operating system package or component

rust-vergen
Operating systems & Components / Operating system package or component

rust-unicode-general-category
Operating systems & Components / Operating system package or component

rust-toml-span
Operating systems & Components / Operating system package or component

rust-tokio-macros
Operating systems & Components / Operating system package or component

rust-tokio
Operating systems & Components / Operating system package or component

rust-tokei12
Operating systems & Components / Operating system package or component

rust-tokei
Operating systems & Components / Operating system package or component

rust-tame-index
Operating systems & Components / Operating system package or component

rust-rustsec
Operating systems & Components / Operating system package or component

rust-pulldown-cmark0.11
Operating systems & Components / Operating system package or component

rust-pulldown-cmark
Operating systems & Components / Operating system package or component

rust-onefetch-manifest
Operating systems & Components / Operating system package or component

rust-onefetch-image
Operating systems & Components / Operating system package or component

rust-onefetch-ascii
Operating systems & Components / Operating system package or component

rust-onefetch
Operating systems & Components / Operating system package or component

rust-nucleo-matcher
Operating systems & Components / Operating system package or component

rust-nucleo
Operating systems & Components / Operating system package or component

rust-gix-worktree-stream
Operating systems & Components / Operating system package or component

rust-gix-worktree-state
Operating systems & Components / Operating system package or component

rust-gix-worktree
Operating systems & Components / Operating system package or component

rust-gix-validate
Operating systems & Components / Operating system package or component

rust-gix-utils
Operating systems & Components / Operating system package or component

rust-gix-url
Operating systems & Components / Operating system package or component

rust-gix-traverse
Operating systems & Components / Operating system package or component

rust-gix-transport
Operating systems & Components / Operating system package or component

rust-gix-trace
Operating systems & Components / Operating system package or component

rust-gix-tempfile
Operating systems & Components / Operating system package or component

rust-gix-submodule
Operating systems & Components / Operating system package or component

rust-gix-status
Operating systems & Components / Operating system package or component

rust-gix-shallow
Operating systems & Components / Operating system package or component

rust-gix-sec
Operating systems & Components / Operating system package or component

rust-gix-revwalk
Operating systems & Components / Operating system package or component

rust-gix-revision
Operating systems & Components / Operating system package or component

rust-gix-refspec
Operating systems & Components / Operating system package or component

rust-gix-ref
Operating systems & Components / Operating system package or component

rust-gix-quote
Operating systems & Components / Operating system package or component

rust-gix-protocol
Operating systems & Components / Operating system package or component

rust-gix-prompt
Operating systems & Components / Operating system package or component

rust-gix-pathspec
Operating systems & Components / Operating system package or component

rust-gix-path
Operating systems & Components / Operating system package or component

rust-gix-packetline-blocking
Operating systems & Components / Operating system package or component

rust-gix-packetline
Operating systems & Components / Operating system package or component

rust-gix-pack
Operating systems & Components / Operating system package or component

rust-gix-odb
Operating systems & Components / Operating system package or component

rust-gix-object
Operating systems & Components / Operating system package or component

rust-gix-negotiate
Operating systems & Components / Operating system package or component

rust-gix-mailmap
Operating systems & Components / Operating system package or component

rust-gix-lock
Operating systems & Components / Operating system package or component

rust-gix-index
Operating systems & Components / Operating system package or component

rust-gix-ignore
Operating systems & Components / Operating system package or component

rust-gix-hashtable
Operating systems & Components / Operating system package or component

rust-gix-hash
Operating systems & Components / Operating system package or component

rust-gix-glob
Operating systems & Components / Operating system package or component

rust-gix-fs
Operating systems & Components / Operating system package or component

rust-gix-filter
Operating systems & Components / Operating system package or component

rust-gix-features
Operating systems & Components / Operating system package or component

rust-gix-discover
Operating systems & Components / Operating system package or component

rust-gix-dir
Operating systems & Components / Operating system package or component

rust-gix-diff
Operating systems & Components / Operating system package or component

rust-gix-credentials
Operating systems & Components / Operating system package or component

rust-gix-config-value
Operating systems & Components / Operating system package or component

rust-gix-config
Operating systems & Components / Operating system package or component

rust-gix-commitgraph
Operating systems & Components / Operating system package or component

rust-gix-command
Operating systems & Components / Operating system package or component

rust-gix-chunk
Operating systems & Components / Operating system package or component

rust-gix-bitmap
Operating systems & Components / Operating system package or component

rust-gix-attributes
Operating systems & Components / Operating system package or component

rust-gix-archive
Operating systems & Components / Operating system package or component

rust-gix-actor
Operating systems & Components / Operating system package or component

rust-gix
Operating systems & Components / Operating system package or component

rust-gengo
Operating systems & Components / Operating system package or component

rust-dua-cli
Operating systems & Components / Operating system package or component

rust-cargo_metadata0.18
Operating systems & Components / Operating system package or component

rust-cargo_metadata
Operating systems & Components / Operating system package or component

rust-cargo-lock
Operating systems & Components / Operating system package or component

rust-cargo-deny
Operating systems & Components / Operating system package or component

rust-cargo
Operating systems & Components / Operating system package or component

helix
Operating systems & Components / Operating system package or component

Vendor Fedoraproject

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Server-Side Request Forgery (SSRF)

EUVDB-ID: #VU96050

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2024-39338

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 42

stgit: before 2.5.1-1.fc42

rust-vergen: before 8.3.2-3.fc42

rust-unicode-general-category: before 1.0.0-1.fc42

rust-toml-span: before 0.4.1-1.fc42

rust-tokio-macros: before 2.5.0-1.fc42

rust-tokio: before 1.43.0-1.fc42

rust-tokei12: before 12.1.2-19.fc42

rust-tokei: before 13.0.0~alpha.8-19.fc42

rust-tame-index: before 0.17.0-1.fc42

rust-rustsec: before 0.30.1-1.fc42

rust-pulldown-cmark0.11: before 0.11.3-1.fc42

rust-pulldown-cmark: before 0.12.2-1.fc42

rust-onefetch-manifest: before 2.23.1-1.fc42

rust-onefetch-image: before 2.23.1-1.fc42

rust-onefetch-ascii: before 2.23.1-1.fc42

rust-onefetch: before 2.23.1-1.fc42

rust-nucleo-matcher: before 0.3.1-1.fc42

rust-nucleo: before 0.5.0-1.fc42

rust-gix-worktree-stream: before 0.19.0-1.fc42

rust-gix-worktree-state: before 0.17.0-1.fc42

rust-gix-worktree: before 0.39.0-1.fc42

rust-gix-validate: before 0.9.3-1.fc42

rust-gix-utils: before 0.1.14-1.fc42

rust-gix-url: before 0.29.0-1.fc42

rust-gix-traverse: before 0.44.0-1.fc42

rust-gix-transport: before 0.45.0-1.fc42

rust-gix-trace: before 0.1.12-1.fc42

rust-gix-tempfile: before 16.0.0-1.fc42

rust-gix-submodule: before 0.17.0-1.fc42

rust-gix-status: before 0.17.0-1.fc42

rust-gix-shallow: before 0.2.0-1.fc42

rust-gix-sec: before 0.10.11-1.fc42

rust-gix-revwalk: before 0.18.0-1.fc42

rust-gix-revision: before 0.32.0-1.fc42

rust-gix-refspec: before 0.28.0-1.fc42

rust-gix-ref: before 0.50.0-1.fc42

rust-gix-quote: before 0.4.15-1.fc42

rust-gix-protocol: before 0.48.0-1.fc42

rust-gix-prompt: before 0.9.1-1.fc42

rust-gix-pathspec: before 0.9.0-1.fc42

rust-gix-path: before 0.10.14-1.fc42

rust-gix-packetline-blocking: before 0.18.2-1.fc42

rust-gix-packetline: before 0.18.3-1.fc42

rust-gix-pack: before 0.57.0-1.fc42

rust-gix-odb: before 0.67.0-1.fc42

rust-gix-object: before 0.47.0-1.fc42

rust-gix-negotiate: before 0.18.0-1.fc42

rust-gix-mailmap: before 0.25.2-1.fc42

rust-gix-lock: before 16.0.0-1.fc42

rust-gix-index: before 0.38.0-1.fc42

rust-gix-ignore: before 0.13.0-1.fc42

rust-gix-hashtable: before 0.7.0-1.fc42

rust-gix-hash: before 0.16.0-1.fc42

rust-gix-glob: before 0.18.0-1.fc42

rust-gix-fs: before 0.13.0-1.fc42

rust-gix-filter: before 0.17.0-1.fc42

rust-gix-features: before 0.40.0-1.fc42

rust-gix-discover: before 0.38.0-1.fc42

rust-gix-dir: before 0.12.0-1.fc42

rust-gix-diff: before 0.50.0-1.fc42

rust-gix-credentials: before 0.27.0-1.fc42

rust-gix-config-value: before 0.14.11-1.fc42

rust-gix-config: before 0.43.0-1.fc42

rust-gix-commitgraph: before 0.26.0-1.fc42

rust-gix-command: before 0.4.1-1.fc42

rust-gix-chunk: before 0.4.11-1.fc42

rust-gix-bitmap: before 0.2.14-1.fc42

rust-gix-attributes: before 0.24.0-1.fc42

rust-gix-archive: before 0.19.0-1.fc42

rust-gix-actor: before 0.33.2-1.fc42

rust-gix: before 0.70.0-1.fc42

rust-gengo: before 0.12.1-1.fc42

rust-dua-cli: before 2.29.2-3.fc42

rust-cargo_metadata0.18: before 0.18.1-1.fc42

rust-cargo_metadata: before 0.19.1-1.fc42

rust-cargo-lock: before 10.1.0-1.fc42

rust-cargo-deny: before 0.16.4-1.fc42

rust-cargo: before 0.79.0-8.fc42

helix: before 25.01.1-1.fc42

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2025-d005a5b394


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Security features bypass

EUVDB-ID: #VU101971

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56201

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a local user to bypass sandbox restrictions.

The vulnerability exists due to improper validation of user-supplied input.  A local user with the ability to control both the filename and the contents of a template can bypass sandbox restrictions.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 42

stgit: before 2.5.1-1.fc42

rust-vergen: before 8.3.2-3.fc42

rust-unicode-general-category: before 1.0.0-1.fc42

rust-toml-span: before 0.4.1-1.fc42

rust-tokio-macros: before 2.5.0-1.fc42

rust-tokio: before 1.43.0-1.fc42

rust-tokei12: before 12.1.2-19.fc42

rust-tokei: before 13.0.0~alpha.8-19.fc42

rust-tame-index: before 0.17.0-1.fc42

rust-rustsec: before 0.30.1-1.fc42

rust-pulldown-cmark0.11: before 0.11.3-1.fc42

rust-pulldown-cmark: before 0.12.2-1.fc42

rust-onefetch-manifest: before 2.23.1-1.fc42

rust-onefetch-image: before 2.23.1-1.fc42

rust-onefetch-ascii: before 2.23.1-1.fc42

rust-onefetch: before 2.23.1-1.fc42

rust-nucleo-matcher: before 0.3.1-1.fc42

rust-nucleo: before 0.5.0-1.fc42

rust-gix-worktree-stream: before 0.19.0-1.fc42

rust-gix-worktree-state: before 0.17.0-1.fc42

rust-gix-worktree: before 0.39.0-1.fc42

rust-gix-validate: before 0.9.3-1.fc42

rust-gix-utils: before 0.1.14-1.fc42

rust-gix-url: before 0.29.0-1.fc42

rust-gix-traverse: before 0.44.0-1.fc42

rust-gix-transport: before 0.45.0-1.fc42

rust-gix-trace: before 0.1.12-1.fc42

rust-gix-tempfile: before 16.0.0-1.fc42

rust-gix-submodule: before 0.17.0-1.fc42

rust-gix-status: before 0.17.0-1.fc42

rust-gix-shallow: before 0.2.0-1.fc42

rust-gix-sec: before 0.10.11-1.fc42

rust-gix-revwalk: before 0.18.0-1.fc42

rust-gix-revision: before 0.32.0-1.fc42

rust-gix-refspec: before 0.28.0-1.fc42

rust-gix-ref: before 0.50.0-1.fc42

rust-gix-quote: before 0.4.15-1.fc42

rust-gix-protocol: before 0.48.0-1.fc42

rust-gix-prompt: before 0.9.1-1.fc42

rust-gix-pathspec: before 0.9.0-1.fc42

rust-gix-path: before 0.10.14-1.fc42

rust-gix-packetline-blocking: before 0.18.2-1.fc42

rust-gix-packetline: before 0.18.3-1.fc42

rust-gix-pack: before 0.57.0-1.fc42

rust-gix-odb: before 0.67.0-1.fc42

rust-gix-object: before 0.47.0-1.fc42

rust-gix-negotiate: before 0.18.0-1.fc42

rust-gix-mailmap: before 0.25.2-1.fc42

rust-gix-lock: before 16.0.0-1.fc42

rust-gix-index: before 0.38.0-1.fc42

rust-gix-ignore: before 0.13.0-1.fc42

rust-gix-hashtable: before 0.7.0-1.fc42

rust-gix-hash: before 0.16.0-1.fc42

rust-gix-glob: before 0.18.0-1.fc42

rust-gix-fs: before 0.13.0-1.fc42

rust-gix-filter: before 0.17.0-1.fc42

rust-gix-features: before 0.40.0-1.fc42

rust-gix-discover: before 0.38.0-1.fc42

rust-gix-dir: before 0.12.0-1.fc42

rust-gix-diff: before 0.50.0-1.fc42

rust-gix-credentials: before 0.27.0-1.fc42

rust-gix-config-value: before 0.14.11-1.fc42

rust-gix-config: before 0.43.0-1.fc42

rust-gix-commitgraph: before 0.26.0-1.fc42

rust-gix-command: before 0.4.1-1.fc42

rust-gix-chunk: before 0.4.11-1.fc42

rust-gix-bitmap: before 0.2.14-1.fc42

rust-gix-attributes: before 0.24.0-1.fc42

rust-gix-archive: before 0.19.0-1.fc42

rust-gix-actor: before 0.33.2-1.fc42

rust-gix: before 0.70.0-1.fc42

rust-gengo: before 0.12.1-1.fc42

rust-dua-cli: before 2.29.2-3.fc42

rust-cargo_metadata0.18: before 0.18.1-1.fc42

rust-cargo_metadata: before 0.19.1-1.fc42

rust-cargo-lock: before 10.1.0-1.fc42

rust-cargo-deny: before 0.16.4-1.fc42

rust-cargo: before 0.79.0-8.fc42

helix: before 25.01.1-1.fc42

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2025-d005a5b394


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###