CVE-2014-9390
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 75.60% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- git-scm/git · mercurial/mercurial · apple/xcode · eclipse/egit · eclipse/jgit · libgit2/libgit2
- Source
- cve@mitre.org
References
- http://article.gmane.org/gmane.linux.kernel/1853266Broken Link
- http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.htmlThird Party Advisory
- http://mercurial.selenic.com/wiki/WhatsNewRelease Notes, Third Party Advisory
- http://securitytracker.com/id?1031404Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT204147Vendor Advisory
- https://github.com/blog/1938-git-client-vulnerability-announcedVendor Advisory
- https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915Third Party Advisory
- https://libgit2.org/security/Product
- https://news.ycombinator.com/item?id=8769667Issue Tracking, Patch, Third Party Advisory
- http://article.gmane.org/gmane.linux.kernel/1853266Broken Link
- http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.htmlThird Party Advisory
- http://mercurial.selenic.com/wiki/WhatsNewRelease Notes, Third Party Advisory
- http://securitytracker.com/id?1031404Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT204147Vendor Advisory
- https://github.com/blog/1938-git-client-vulnerability-announcedVendor Advisory
- https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915Third Party Advisory
- https://libgit2.org/security/Product
- https://news.ycombinator.com/item?id=8769667Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.