git: Command injection via malicious ssh URLs
Published Oct 4, 2017
8.8
HIGHCVSS 3.0
EPSS 77.82%
Description
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
Affected products
No data.
- ≤ 2.7.5
- 2.8.0
- 2.8.0
- 2.8.0
- 2.8.0
- 2.8.0
- 2.8.1
- 2.8.2
- 2.8.3
- 2.8.4
- 2.8.5
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.0
- 2.9.1
- 2.9.2
- 2.9.3
- 2.9.4
- 2.10.0
- 2.10.0
- 2.10.0
- 2.10.0
- 2.10.1
- 2.10.2
- 2.10.3
- 2.11.0
- 2.11.0
- 2.11.0
- 2.11.0
- 2.11.0
- 2.11.1
- 2.11.2
- 2.12.0
- 2.12.0
- 2.12.0
- 2.12.0
- 2.12.1
- 2.12.2
- 2.12.3
- 2.13.0
- 2.13.0
- 2.13.0
- 2.13.0
- 2.13.1
- 2.13.2
- 2.13.3
- 2.13.4
- 2.14.0
- 2.14.0
- 2.14.0
No data.
Red Hat Enterprise Linux 6
git-0:1.7.1-9.el6_9
Fixed · RHSA-2017:2485
Red Hat Enterprise Linux 7
git-0:1.8.3.1-12.el7_4
Fixed · RHSA-2017:2484
Red Hat Mobile Application Platform 4.5
fh-system-dump-tool-0:1.0.0-5.el7
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
fping-0:3.10-4.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
nagios-0:4.0.8-8.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
nagios-plugins-0:2.0.3-3.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
perl-Crypt-CBC-0:2.33-2.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
perl-Crypt-DES-0:2.05-20.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
perl-Net-SNMP-0:6.0.1-7.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
phantomjs-0:1.9.7-3.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
python-meld3-0:0.6.10-1.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
qstat-0:2.11-13.20080912svn311.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
radiusclient-ng-0:0.5.6-9.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
redis-0:2.8.21-2.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
rhmap-fh-openshift-templates-0:4.5.0-11.el7
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
rhmap-mod_authnz_external-0:3.3.1-7.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
rhmap45/fh-aaa:1.0.5-12
Fixed · RHSA-2017:2675
Red Hat Mobile Application Platform 4.5
sendEmail-0:1.56-2.el7
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
ssmtp-0:2.64-14.el7map
Fixed · RHSA-2017:2674
Red Hat Mobile Application Platform 4.5
supervisor-0:3.1.3-3.el7map
Fixed · RHSA-2017:2674
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-git29-git-0:2.9.3-3.el6
Fixed · RHSA-2017:2491
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-git29-git-0:2.9.3-3.el7
Fixed · RHSA-2017:2491
Red Hat BPM Suite 6
jgit
Not affected
Red Hat JBoss A-MQ 6
fabric8
Not affected
Red Hat JBoss BRMS 6
jgit
Not affected
Red Hat JBoss Data Virtualization 6
jgit
Not affected
Red Hat JBoss Fuse 6
camel
Not affected
Red Hat JBoss Fuse Service Works 6
jgit
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | git-0:1.7.1-9.el6_9 | Fixed | RHSA-2017:2485 |
| Red Hat Enterprise Linux 7 | git-0:1.8.3.1-12.el7_4 | Fixed | RHSA-2017:2484 |
| Red Hat Mobile Application Platform 4.5 | fh-system-dump-tool-0:1.0.0-5.el7 | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | fping-0:3.10-4.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | nagios-0:4.0.8-8.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | nagios-plugins-0:2.0.3-3.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | perl-Crypt-CBC-0:2.33-2.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | perl-Crypt-DES-0:2.05-20.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | perl-Net-SNMP-0:6.0.1-7.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | phantomjs-0:1.9.7-3.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | python-meld3-0:0.6.10-1.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | qstat-0:2.11-13.20080912svn311.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | radiusclient-ng-0:0.5.6-9.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | redis-0:2.8.21-2.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | rhmap-fh-openshift-templates-0:4.5.0-11.el7 | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | rhmap-mod_authnz_external-0:3.3.1-7.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | rhmap45/fh-aaa:1.0.5-12 | Fixed | RHSA-2017:2675 |
| Red Hat Mobile Application Platform 4.5 | sendEmail-0:1.56-2.el7 | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | ssmtp-0:2.64-14.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Mobile Application Platform 4.5 | supervisor-0:3.1.3-3.el7map | Fixed | RHSA-2017:2674 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-git29-git-0:2.9.3-3.el6 | Fixed | RHSA-2017:2491 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-git29-git-0:2.9.3-3.el7 | Fixed | RHSA-2017:2491 |
| Red Hat BPM Suite 6 | jgit | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | fabric8 | Not affected | n/a |
| Red Hat JBoss BRMS 6 | jgit | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | jgit | Not affected | n/a |
| Red Hat JBoss Fuse 6 | camel | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | jgit | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://blog.recurity-labs.com/2017-08-10/scm-vulns
- http://www.debian.org/security/2017/dsa-3934 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/100283 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039131 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2484 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2485 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2491 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2674 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2675 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-1000117 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1480386 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1408 Advisory
- https://lkml.org/lkml/2017/8/10/757
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000117
- https://security.gentoo.org/glsa/201709-10 vendor-advisoryx_refsource_GENTOOThird Party AdvisoryVDB Entry
- https://support.apple.com/HT208103 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-1000117
- https://www.exploit-db.com/exploits/42599/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.html x_refsource_MISC
Change history (0)
No recorded changes yet.