Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8386

Опубликовано: 01 июн. 2017
Источник: debian
EPSS Высокий

Описание

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitfixed1:2.11.0-3package

Примечания

  • http://lkml.iu.edu/hypermail/linux/kernel/1705.1/01337.html

  • http://lkml.iu.edu/hypermail/linux/kernel/1705.1/01346.html

  • https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/

  • https://git.kernel.org/pub/scm/git/git.git/commit/?id=3ec804490a265f4c418a321428c12f3f18b7eff5

EPSS

Процентиль: 99%
0.75646
Высокий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 5
redhat
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 8.8
nvd
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

suse-cvrf
больше 8 лет назад

Security update for git

suse-cvrf
больше 8 лет назад

Security update for git

EPSS

Процентиль: 99%
0.75646
Высокий