Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9938

Опубликовано: 20 мар. 2017
Источник: debian

Описание

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitfixed1:2.0.0~rc2-1package
gitnot-affectedwheezypackage

Примечания

  • https://github.com/git/git/commit/8976500cbbb13270398d3b3e07a17b8cc7bff43f

  • https://github.com/njhartwell/pw3nage

  • Vulnerability likely introduced by the "pc_mode" in https://github.com/git/git/commit/1bfc51ac814125de03ddf1900245e42d6ce0d250

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

CVSS3: 7.8
redhat
больше 11 лет назад

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

CVSS3: 8.8
nvd
больше 8 лет назад

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

CVSS3: 8.8
github
больше 3 лет назад

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

oracle-oval
больше 8 лет назад

ELSA-2017-2004: git security and bug fix update (MODERATE)