CVE-2008-5916
Summary
| CVE | CVE-2008-5916 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-21 02:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and executing a crafted gitweb query. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Git | Git | 1.4.3.1 | All | All | All |
| Application | Git | Git | 1.4.3.2 | All | All | All |
| Application | Git | Git | 1.4.3.3 | All | All | All |
| Application | Git | Git | 1.4.3.4 | All | All | All |
| Application | Git | Git | 1.4.3.5 | All | All | All |
| Application | Git | Git | 1.4.4 | All | All | All |
| Application | Git | Git | 1.4.4.1 | All | All | All |
| Application | Git | Git | 1.4.4.2 | All | All | All |
| Application | Git | Git | 1.4.4.3 | All | All | All |
| Application | Git | Git | 1.4.4.4 | All | All | All |
| Application | Git | Git | 1.5.0 | All | All | All |
| Application | Git | Git | 1.5.0 | rc2 | All | All |
| Application | Git | Git | 1.5.0 | rc3 | All | All |
| Application | Git | Git | 1.5.0 | rc4 | All | All |
| Application | Git | Git | 1.5.0.1 | All | All | All |
| Application | Git | Git | 1.5.0.2 | All | All | All |
| Application | Git | Git | 1.5.0.3 | All | All | All |
| Application | Git | Git | 1.5.0.4 | All | All | All |
| Application | Git | Git | 1.5.0.5 | All | All | All |
| Application | Git | Git | 1.5.0.6 | All | All | All |
| Application | Git | Git | 1.5.0.7 | All | All | All |
| Application | Git | Git | 1.5.1 | All | All | All |
| Application | Git | Git | 1.5.1.1 | All | All | All |
| Application | Git | Git | 1.5.1.2 | All | All | All |
| Application | Git | Git | 1.5.1.3 | All | All | All |
| Application | Git | Git | 1.5.1.4 | All | All | All |
| Application | Git | Git | 1.5.1.5 | All | All | All |
| Application | Git | Git | 1.5.1.6 | All | All | All |
| Application | Git | Git | 1.5.2 | All | All | All |
| Application | Git | Git | 1.5.2.1 | All | All | All |
| Application | Git | Git | 1.5.2.2 | All | All | All |
| Application | Git | Git | 1.5.2.3 | All | All | All |
| Application | Git | Git | 1.5.2.4 | All | All | All |
| Application | Git | Git | 1.5.2.5 | All | All | All |
| Application | Git | Git | 1.5.3 | All | All | All |
| Application | Git | Git | 1.5.3 | rc4 | All | All |
| Application | Git | Git | 1.5.3 | rc5 | All | All |
| Application | Git | Git | 1.5.3 | rc7 | All | All |
| Application | Git | Git | 1.5.3.1 | All | All | All |
| Application | Git | Git | 1.5.3.2 | All | All | All |
| Application | Git | Git | 1.5.3.3 | All | All | All |
| Application | Git | Git | 1.5.3.4 | All | All | All |
| Application | Git | Git | 1.5.3.5 | All | All | All |
| Application | Git | Git | 1.5.3.6 | All | All | All |
| Application | Git | Git | 1.5.3.7 | All | All | All |
| Application | Git | Git | 1.5.3.8 | All | All | All |
| Application | Git | Git | 1.5.4 | All | All | All |
| Application | Git | Git | 1.5.4 | rc0 | All | All |
| Application | Git | Git | 1.5.4 | rc1 | All | All |
| Application | Git | Git | 1.5.4 | rc1.1136.g2794 | All | All |
| Application | Git | Git | 1.5.4 | rc2 | All | All |
| Application | Git | Git | 1.5.4 | rc3 | All | All |
| Application | Git | Git | 1.5.4 | rc4 | All | All |
| Application | Git | Git | 1.5.4 | rc5 | All | All |
| Application | Git | Git | 1.5.4.1 | All | All | All |
| Application | Git | Git | 1.5.4.2 | All | All | All |
| Application | Git | Git | 1.5.4.3 | All | All | All |
| Application | Git | Git | 1.5.4.4 | All | All | All |
| Application | Git | Git | 1.5.4.5 | All | All | All |
| Application | Git | Git | 1.5.4.6 | All | All | All |
| Application | Git | Git | 1.5.5 | All | All | All |
| Application | Git | Git | 1.5.5 | rc1 | All | All |
| Application | Git | Git | 1.5.5 | rc2 | All | All |
| Application | Git | Git | 1.5.5 | rc3 | All | All |
| Application | Git | Git | 1.5.5.1 | All | All | All |
| Application | Git | Git | 1.5.5.2 | All | All | All |
| Application | Git | Git | 1.5.5.3 | All | All | All |
| Application | Git | Git | 1.5.5.3 | r1 | All | All |
| Application | Git | Git | 1.5.5.4 | All | All | All |
| Application | Git | Git | 1.5.5.5 | All | All | All |
| Application | Git | Git | 1.5.6 | All | All | All |
| Application | Git | Git | 1.5.6.1 | All | All | All |
| Application | Git | Git | 1.5.6.2 | All | All | All |
| Application | Git | Git | 1.5.6.3 | All | All | All |
| Application | Git | Git | 1.5.6.4 | All | All | All |
| Application | Git | Git | 1.5.6.5 | All | All | All |
| Application | Git | Git | 1.6.0 | All | All | All |
| Application | Git | Git | 1.6.0 | rc1 | All | All |
| Application | Git | Git | 1.6.0 | rc2 | All | All |
| Application | Git | Git | 1.6.0 | rc3 | All | All |
| Application | Git | Git | 1.6.0.1 | All | All | All |
| Application | Git | Git | 1.6.0.2 | All | All | All |
| Application | Git | Git | 1.6.0.3 | All | All | All |
| Application | Git | Git | 1.6.0.4 | All | All | All |
| Application | Git | Git | 1.6.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 8 Update: git-1.5.4.3-3.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| oss-security - Re: CVE request -- git | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Fedora update for git - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| osvdb.org/50918 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo Linux Documentation -- git: Multiple vulnerabilties | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Ubuntu update for git-core - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - CVE request -- git | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| gitweb local privilege escalation - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| [SECURITY] Fedora 9 Update: git-1.5.6.6-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| USN-723-1: Git vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| '[Security] gitweb local privilege escalation (fix)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo update for git - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.