<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p>==========================================================================</p>
<div id=":16f" class="a3s aiL ">
Ubuntu Security Notice USN-7130-1<br>
November 26, 2024<br>
<br>
gh vulnerability<br>
==============================<wbr>==============================<wbr>==============<br>
<br>
A security issue affects these releases of Ubuntu and its
derivatives:<br>
<br>
- Ubuntu 24.10<br>
- Ubuntu 24.04 LTS<br>
<br>
Summary:<br>
<br>
GitHub CLI could be made to run programs as your login if it <br>
connected to a malicious server.<br>
<br>
Software Description:<br>
- gh: GitHub CLI, GitHub’s official command line tool<br>
<br>
Details:<br>
<br>
It was discovered that GitHub CLI incorrectly handled username<br>
validation. An attacker could possibly use this issue to perform <br>
remote code execution if the user connected to a malicious server.<br>
(CVE-2024-52308)<br>
<br>
Update instructions:<br>
<br>
The problem can be corrected by updating your system to the
following<br>
package versions:<br>
<br>
Ubuntu 24.10<br>
gh 2.46.0-1ubuntu0.2<br>
<br>
Ubuntu 24.04 LTS<br>
gh 2.45.0-1ubuntu0.2+esm1<br>
Available with Ubuntu Pro<br>
<br>
In general, a standard system update will make all the necessary
changes.<br>
<br>
References:<br>
<a href="https://ubuntu.com/security/notices/USN-7130-1"
rel="noreferrer" target="_blank"
data-saferedirecturl="https://www.google.com/url?q=https://ubuntu.com/security/notices/USN-7130-1&source=gmail&ust=1732735834761000&usg=AOvVaw11PW0EeFfTqQB_aenMTOrp">https://ubuntu.com/security/no<wbr>tices/USN-7130-1</a><br>
CVE-2024-52308<br>
<br>
Package Information:<br>
<a
href="https://launchpad.net/ubuntu/+source/gh/2.46.0-1ubuntu0.2"
rel="noreferrer" target="_blank"
data-saferedirecturl="https://www.google.com/url?q=https://launchpad.net/ubuntu/%2Bsource/gh/2.46.0-1ubuntu0.2&source=gmail&ust=1732735834761000&usg=AOvVaw1W_xLGVkDl7AYlqGTazAi6">https://launchpad.net/ubuntu/+<wbr>source/gh/2.46.0-1ubuntu0.2</a></div>
</body>
</html>