Логотип exploitDog
bind:"CVE-2017-1000117"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-1000117"

Количество 11

Количество 11

ubuntu логотип

CVE-2017-1000117

около 8 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
EPSS: Высокий
redhat логотип

CVE-2017-1000117

больше 8 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 6.3
EPSS: Высокий
nvd логотип

CVE-2017-1000117

около 8 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
EPSS: Высокий
debian логотип

CVE-2017-1000117

около 8 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsus ...

CVSS3: 8.8
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2017:2331-1

около 8 лет назад

Security update for git

EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2017:2182-1

около 8 лет назад

Security update for git

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2017:2320-1

около 8 лет назад

Security update for git

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2017:2225-1

около 8 лет назад

Security update for git

EPSS: Высокий
github логотип

GHSA-q5x8-47cx-6m4p

больше 3 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
EPSS: Высокий
oracle-oval логотип

ELSA-2017-2485

около 8 лет назад

ELSA-2017-2485: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-2484

около 8 лет назад

ELSA-2017-2484: git security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
71%
Высокий
около 8 лет назад
redhat логотип
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 6.3
71%
Высокий
больше 8 лет назад
nvd логотип
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
71%
Высокий
около 8 лет назад
debian логотип
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsus ...

CVSS3: 8.8
71%
Высокий
около 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2331-1

Security update for git

71%
Высокий
около 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2182-1

Security update for git

71%
Высокий
около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2320-1

Security update for git

71%
Высокий
около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2225-1

Security update for git

71%
Высокий
около 8 лет назад
github логотип
GHSA-q5x8-47cx-6m4p

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 8.8
71%
Высокий
больше 3 лет назад
oracle-oval логотип
ELSA-2017-2485

ELSA-2017-2485: git security update (IMPORTANT)

около 8 лет назад
oracle-oval логотип
ELSA-2017-2484

ELSA-2017-2484: git security update (IMPORTANT)

около 8 лет назад

Уязвимостей на страницу