Логотип exploitDog
bind:CVE-2017-9800
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-9800

Количество 10

Количество 10

ubuntu логотип

CVE-2017-9800

больше 8 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2017-9800

больше 8 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 6.3
EPSS: Средний
nvd логотип

CVE-2017-9800

больше 8 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2017-9800

больше 8 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion client ...

CVSS3: 9.8
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:2183-1

около 8 лет назад

Security update for subversion

EPSS: Средний
github логотип

GHSA-34wf-vr8w-7xh4

больше 3 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
EPSS: Средний
oracle-oval логотип

ELSA-2017-2480

около 8 лет назад

ELSA-2017-2480: subversion security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2017-02070

больше 8 лет назад

Уязвимость служб svn:externals и svn:sync-from-url централизованной системы управления версиями Subversion, позволяющая нарушителю выполнить произвольную shell-команду

CVSS2: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2017:2163-1

больше 8 лет назад

Security update for subversion

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2200-1

около 8 лет назад

Security update for subversion

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-9800

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
50%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-9800

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 6.3
50%
Средний
больше 8 лет назад
nvd логотип
CVE-2017-9800

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
50%
Средний
больше 8 лет назад
debian логотип
CVE-2017-9800

A maliciously constructed svn+ssh:// URL would cause Subversion client ...

CVSS3: 9.8
50%
Средний
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2183-1

Security update for subversion

50%
Средний
около 8 лет назад
github логотип
GHSA-34wf-vr8w-7xh4

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
50%
Средний
больше 3 лет назад
oracle-oval логотип
ELSA-2017-2480

ELSA-2017-2480: subversion security update (IMPORTANT)

около 8 лет назад
fstec логотип
BDU:2017-02070

Уязвимость служб svn:externals и svn:sync-from-url централизованной системы управления версиями Subversion, позволяющая нарушителю выполнить произвольную shell-команду

CVSS2: 7.5
50%
Средний
больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2163-1

Security update for subversion

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2200-1

Security update for subversion

около 8 лет назад

Уязвимостей на страницу