Source: rust-gix-worktree-state X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security
Hi, The following vulnerability was published for rust-gix-worktree-state. CVE-2025-22620[0]: | gitoxide is an implementation of git written in Rust. Prior to | 0.17.0, gix-worktree-state specifies 0777 permissions when checking | out executable files, intending that the umask will restrict them | appropriately. But one of the strategies it uses to set permissions | is not subject to the umask. This causes files in a repository to be | world-writable in some situations. This vulnerability is fixed in | 0.17.0. https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-fqmf-w4xh-33rh https://rustsec.org/advisories/RUSTSEC-2025-0001.html If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-22620 https://www.cve.org/CVERecord?id=CVE-2025-22620 Please adjust the affected versions in the BTS as needed.