CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 77.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 77.82% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- git-scm/git
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3934
- http://www.securityfocus.com/bid/100283Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039131Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2484
- https://access.redhat.com/errata/RHSA-2017:2485
- https://access.redhat.com/errata/RHSA-2017:2491
- https://access.redhat.com/errata/RHSA-2017:2674
- https://access.redhat.com/errata/RHSA-2017:2675
- https://security.gentoo.org/glsa/201709-10Third Party Advisory, VDB Entry
- https://support.apple.com/HT208103Third Party Advisory
- https://www.exploit-db.com/exploits/42599/Third Party Advisory, VDB Entry
- https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.html
- http://www.debian.org/security/2017/dsa-3934
- http://www.securityfocus.com/bid/100283Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039131Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2484
- https://access.redhat.com/errata/RHSA-2017:2485
- https://access.redhat.com/errata/RHSA-2017:2491
- https://access.redhat.com/errata/RHSA-2017:2674
- https://access.redhat.com/errata/RHSA-2017:2675
- https://security.gentoo.org/glsa/201709-10Third Party Advisory, VDB Entry
- https://support.apple.com/HT208103Third Party Advisory
- https://www.exploit-db.com/exploits/42599/Third Party Advisory, VDB Entry
- https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.