CVE-2012-4548

medium
Published 2012-11-11 · Modified 2026-04-29
CVSS v3
CVSS v2
6.0
VIR risk
6.0

Description

Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4548

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51167

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50734

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
lars_hjemlicgit{"endIncluding":"0.9.0.3"}
lars_hjemlicgit0.1
lars_hjemlicgit0.2
lars_hjemlicgit0.3
lars_hjemlicgit0.4
lars_hjemlicgit0.5
lars_hjemlicgit0.6
lars_hjemlicgit0.6.1
lars_hjemlicgit0.6.2
lars_hjemlicgit0.6.3
lars_hjemlicgit0.7
lars_hjemlicgit0.7.1
lars_hjemlicgit0.7.2
lars_hjemlicgit0.8
lars_hjemlicgit0.8.1
lars_hjemlicgit0.8.1.1
lars_hjemlicgit0.8.2
lars_hjemlicgit0.8.2.1
lars_hjemlicgit0.8.2.2
lars_hjemlicgit0.8.3
lars_hjemlicgit0.8.3.1
lars_hjemlicgit0.8.3.2
lars_hjemlicgit0.8.3.3
lars_hjemlicgit0.8.3.4
lars_hjemlicgit0.8.3.5
lars_hjemlicgit0.9
lars_hjemlicgit0.9.0.1
lars_hjemlicgit0.9.0.2

References

Verify integrity in audit chain (admin only). AS-IS.