Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7545

Опубликовано: 05 окт. 2015
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

A flaw was found in the way the git-remote-ext helper processed certain URLs. If a user had Git configured to automatically clone submodules from untrusted repositories, an attacker could inject commands into the URL of a submodule, allowing them to execute arbitrary code on the user's system.

Меры по смягчению последствий

Avoid recursive cloning or updating of git submodules without checking the submodule URL. Non-recursive cloning is the default in git, so user needs to change this to become vulnerable ("e.g. by specifying --recursive").

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitNot affected
Red Hat Enterprise Linux 7gitFixedRHSA-2015:256108.12.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6git19-gitFixedRHSA-2015:251525.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSgit19-gitFixedRHSA-2015:251525.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSgit19-gitFixedRHSA-2015:251525.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSgit19-gitFixedRHSA-2015:251525.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 7git19-gitFixedRHSA-2015:251525.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSgit19-gitFixedRHSA-2015:251525.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1269794git: arbitrary code execution via crafted URLs

EPSS

Процентиль: 97%
0.31254
Средний

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

CVSS3: 9.8
nvd
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

CVSS3: 9.8
debian
больше 9 лет назад

The (1) git-remote-ext and (2) unspecified other remote helper program ...

suse-cvrf
больше 9 лет назад

Recommended update for git

suse-cvrf
больше 9 лет назад

Recommended update for git

EPSS

Процентиль: 97%
0.31254
Средний

6.8 Medium

CVSS2