Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14176

Опубликовано: 26 авг. 2017
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bzrWill not fix
Red Hat Enterprise Linux 7bzrWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1486685bzr: does not strip bzr+ssh SSH options

EPSS

Процентиль: 92%
0.05978
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

CVSS3: 8.8
nvd
больше 8 лет назад

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

CVSS3: 8.8
msrc
10 месяцев назад

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands

CVSS3: 8.8
debian
больше 8 лет назад

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attac ...

suse-cvrf
около 8 лет назад

Security update for bzr

EPSS

Процентиль: 92%
0.05978
Низкий

5 Medium

CVSS3