CVE-2024-35197 affects gitoxide, a pure Rust Git implementation, specifically on Windows systems. The vulnerability allows a malicious repository to cause indefinite blocking or write arbitrary data to legacy device names (e.g., CON) when cloned, potentially leading to denial of service or other harmful effects. Rated Medium (CVSS 5.4), it requires user interaction (cloning a malicious repository) and has low impact on integrity and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Byron | Gitoxide | < 0.36.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.