Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9390

Опубликовано: 12 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

РелизСтатусПримечание
artful

released

1:2.1.4-2
bionic

released

1:2.1.4-2
cosmic

released

1:2.1.4-2
devel

released

1:2.1.4-2
disco

released

1:2.1.4-2
eoan

released

1:2.1.4-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:1.9.1-1ubuntu0.1]]
esm-infra/bionic

released

1:2.1.4-2
esm-infra/focal

released

1:2.1.4-2
esm-infra/xenial

released

1:2.1.4-2

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

3.7.1-2
cosmic

not-affected

3.7.1-2
devel

not-affected

3.7.1-2
disco

not-affected

3.7.1-2
eoan

not-affected

3.7.1-2
esm-apps/bionic

not-affected

3.7.1-2
esm-apps/focal

not-affected

3.7.1-2
esm-apps/jammy

not-affected

3.7.1-2
esm-apps/noble

not-affected

3.7.1-2

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

0.24.1-2
cosmic

not-affected

0.24.1-2
devel

not-affected

0.24.1-2
disco

not-affected

0.24.1-2
eoan

not-affected

0.24.1-2
esm-apps/bionic

not-affected

0.24.1-2
esm-apps/focal

not-affected

0.24.1-2
esm-apps/jammy

not-affected

0.24.1-2
esm-apps/xenial

not-affected

0.24.1-2

Показывать по

РелизСтатусПримечание
artful

not-affected

3.1.2-2
bionic

not-affected

3.1.2-2
cosmic

not-affected

3.1.2-2
devel

not-affected

3.1.2-2
disco

not-affected

3.1.2-2
eoan

not-affected

3.1.2-2
esm-apps/bionic

not-affected

3.1.2-2
esm-apps/focal

not-affected

3.1.2-2
esm-apps/jammy

not-affected

3.1.2-2
esm-apps/noble

not-affected

3.1.2-2

Показывать по

EPSS

Процентиль: 98%
0.5996
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
около 11 лет назад

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

CVSS3: 9.8
nvd
почти 6 лет назад

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

CVSS3: 9.8
debian
почти 6 лет назад

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x befo ...

CVSS3: 9.8
github
больше 3 лет назад

JGit Improper Input Validation vulnerability

EPSS

Процентиль: 98%
0.5996
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2014-9390