[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-17456Date: (C)2018-10-08   (M)2024-02-22


Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.8CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
SECTRACK-1041811
BID-105523
BID-107511
https://seclists.org/bugtraq/2019/Mar/30
EXPLOIT-DB-45548
EXPLOIT-DB-45631
DSA-4311
RHSA-2018:3408
RHSA-2018:3505
RHSA-2018:3541
RHSA-2020:0316
USN-3791-1
http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.html
https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404
https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46
https://marc.info/?l=git&m=153875888916397&w=2
https://www.openwall.com/lists/oss-security/2018/10/06/3
openSUSE-SU-2020:0598

CPE    8
cpe:/o:debian:debian_linux:9.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
cpe:/o:redhat:enterprise_linux:7.0
cpe:/o:redhat:enterprise_linux_server:7.0
...
CWE    1
CWE-88
OVAL    26
oval:org.secpod.oval:def:89002056
oval:org.secpod.oval:def:704345
oval:org.secpod.oval:def:89003444
oval:org.secpod.oval:def:70611
...

© SecPod Technologies