8.8

CVE-2017-8386

Exploit
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Git ≫ Git-shell Version -
Opensuse ≫ Leap Version 42.1
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.10
Canonical ≫ Ubuntu Linux Version 17.04
Fedoraproject ≫ Fedora Version 24
Fedoraproject ≫ Fedora Version 25
Fedoraproject ≫ Fedora Version 26
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.39% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://access.redhat.com/errata/RHSA-2017:2004
http://lists.opensuse.org/opensuse-updates/2017-05/msg00090.html
Third Party Advisory
Mailing List
http://public-inbox.org/git/xmqq8tm5ziat.fsf%40gitster.mtv.corp.google.com/
http://www.debian.org/security/2017/dsa-3848
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/98409
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038479
Third Party Advisory
http://www.ubuntu.com/usn/USN-3287-1
Third Party Advisory
Exploit
https://access.redhat.com/errata/RHSA-2017:2491
https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/
Third Party Advisory
Mitigation
https://kernel.googlesource.com/pub/scm/git/git/+/3ec804490a265f4c418a321428c12f3f18b7eff5
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ISHYFLM2ACYHHY3JHCLF75X7UF4ZMDM/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPYRN7APMHY4ZFDPAKD22J5R4QJFY2JP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDS3LSJJ3YGGQYIVPKQDVOCXWDSF6JGF/
https://security.gentoo.org/glsa/201706-04