Upstream information
Description
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
SUSE Bugzilla entry: 1226420 [IN_PROGRESS]SUSE Security Advisories:
- openSUSE-SU-2024:0210-1, published Mon Jul 22 16:48:45 2024
 
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| SUSE Package Hub 15 SP5 | 
  |  Patchnames:  openSUSE-2024-210  | 
| SUSE Package Hub 15 SP6 | 
  |  Patchnames:  openSUSE-2024-210  | 
| openSUSE Leap 15.5 | 
  |  Patchnames:  openSUSE-2024-210  | 
| openSUSE Leap 15.6 | 
  |  Patchnames:  openSUSE-2024-210  | 
| openSUSE Tumbleweed | 
  |  Patchnames:  openSUSE-Tumbleweed-2024-14123  | 
SUSE Timeline for this CVE
CVE page created: Sun Jun 16 18:00:01 2024CVE page last modified: Sun Nov 2 00:20:23 2025