Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19486

Опубликовано: 24 окт. 2018
Источник: redhat
CVSS3: 7.5

Описание

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitNot affected
Red Hat Enterprise Linux 7gitNot affected
Red Hat Enterprise Linux 8gitNot affected
Red Hat Software Collectionsrh-git29-gitNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git218-gitFixedRHSA-2018:380010.12.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-git218-gitFixedRHSA-2018:380010.12.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-git218-gitFixedRHSA-2018:380010.12.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-git218-gitFixedRHSA-2018:380010.12.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=1653143git: Improper handling of PATH allows for commands to be executed from the current directory

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

CVSS3: 9.8
nvd
около 7 лет назад

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

CVSS3: 9.8
debian
около 7 лет назад

Git before 2.19.2 on Linux and UNIX executes commands from the current ...

suse-cvrf
около 7 лет назад

Security update for git

suse-cvrf
около 7 лет назад

Security update for git

7.5 High

CVSS3