CVE-2017-14867
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 36.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 36.00% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- git-scm/git · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/09/26/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101060Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039431Third Party Advisory, VDB Entry
- https://bugs.debian.org/876854Issue Tracking, Mailing List, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00246.htmlMailing List, Third Party Advisory
- https://public-inbox.org/git/xmqqy3p29ekj.fsf%40gitster.mtv.corp.google.com/T/#u
- https://www.debian.org/security/2017/dsa-3984Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/09/26/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101060Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039431Third Party Advisory, VDB Entry
- https://bugs.debian.org/876854Issue Tracking, Mailing List, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00246.htmlMailing List, Third Party Advisory
- https://public-inbox.org/git/xmqqy3p29ekj.fsf%40gitster.mtv.corp.google.com/T/#u
- https://www.debian.org/security/2017/dsa-3984Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.