Google: dev-vcs/git: security update to 17800.570.23

low Tenable Cloud Security Plugin ID 454973

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted
repository and runs gitk without additional command arguments, files for which the user has write
permission can be created and truncated. The option Support per-file encoding must have been enabled
before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of
this line is used in the main window (regardless of whether Support per-file encoding is enabled or not).
This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
(CVE-2025-27613)

Solution

Update the dev-vcs/git library and its related packages to version 17800.570.23 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: Low

ID: 454973

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2025-27613

CVSS v3

Risk Factor: Low

Base Score: 3.6

Temporal Score: 3.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/8/2025

Reference Information

CVE: CVE-2025-27613