<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>==========================================================================</p>
    <div id=":16f" class="a3s aiL ">
      Ubuntu Security Notice USN-7130-1<br>
      November 26, 2024<br>
      <br>
      gh vulnerability<br>
      ==============================<wbr>==============================<wbr>==============<br>
      <br>
      A security issue affects these releases of Ubuntu and its
      derivatives:<br>
      <br>
      - Ubuntu 24.10<br>
      - Ubuntu 24.04 LTS<br>
      <br>
      Summary:<br>
      <br>
      GitHub CLI could be made to run programs as your login if it <br>
      connected to a malicious server.<br>
      <br>
      Software Description:<br>
      - gh: GitHub CLI, GitHub’s official command line tool<br>
      <br>
      Details:<br>
      <br>
      It was discovered that GitHub CLI incorrectly handled username<br>
      validation. An attacker could possibly use this issue to perform <br>
      remote code execution if the user connected to a malicious server.<br>
      (CVE-2024-52308)<br>
      <br>
      Update instructions:<br>
      <br>
      The problem can be corrected by updating your system to the
      following<br>
      package versions:<br>
      <br>
      Ubuntu 24.10<br>
        gh                              2.46.0-1ubuntu0.2<br>
      <br>
      Ubuntu 24.04 LTS<br>
        gh                              2.45.0-1ubuntu0.2+esm1<br>
                                        Available with Ubuntu Pro<br>
      <br>
      In general, a standard system update will make all the necessary
      changes.<br>
      <br>
      References:<br>
        <a href="https://ubuntu.com/security/notices/USN-7130-1"
        rel="noreferrer" target="_blank"
data-saferedirecturl="https://www.google.com/url?q=https://ubuntu.com/security/notices/USN-7130-1&source=gmail&ust=1732735834761000&usg=AOvVaw11PW0EeFfTqQB_aenMTOrp">https://ubuntu.com/security/no<wbr>tices/USN-7130-1</a><br>
        CVE-2024-52308<br>
      <br>
      Package Information:<br>
        <a
        href="https://launchpad.net/ubuntu/+source/gh/2.46.0-1ubuntu0.2"
        rel="noreferrer" target="_blank"
data-saferedirecturl="https://www.google.com/url?q=https://launchpad.net/ubuntu/%2Bsource/gh/2.46.0-1ubuntu0.2&source=gmail&ust=1732735834761000&usg=AOvVaw1W_xLGVkDl7AYlqGTazAi6">https://launchpad.net/ubuntu/+<wbr>source/gh/2.46.0-1ubuntu0.2</a></div>
  </body>
</html>