CVE-2015-7545
Summary
| CVE | CVE-2015-7545 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-13 15:59:01 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-20 | CWE-284 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.10 | All | All | All |
| Application | Git Project | Git | 2.4.0 | All | All | All |
| Application | Git Project | Git | 2.4.1 | All | All | All |
| Application | Git Project | Git | 2.4.2 | All | All | All |
| Application | Git Project | Git | 2.4.3 | All | All | All |
| Application | Git Project | Git | 2.4.4 | All | All | All |
| Application | Git Project | Git | 2.4.5 | All | All | All |
| Application | Git Project | Git | 2.4.6 | All | All | All |
| Application | Git Project | Git | 2.4.7 | All | All | All |
| Application | Git Project | Git | 2.4.8 | All | All | All |
| Application | Git Project | Git | 2.4.9 | All | All | All |
| Application | Git Project | Git | 2.5.0 | All | All | All |
| Application | Git Project | Git | 2.5.1 | All | All | All |
| Application | Git Project | Git | 2.5.2 | All | All | All |
| Application | Git Project | Git | 2.5.3 | All | All | All |
| Application | Git Project | Git | 2.6.0 | All | All | All |
| Application | Git Project | Git | All | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Application | Redhat | Software Collections | 1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1269794 – (CVE-2015-7545) CVE-2015-7545 git: arbitrary code execution via crafted URLs | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Git CVE-2015-7545 Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| git/2.4.10.txt at master · git/git · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Vendor Advisory |
| GIT git-remote-ext Helper URL Processing Lets Remote Users Execute Arbitrary Commands on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.slackware.com | |
| Git: Multiple vulnerabilities (GLSA 201605-01) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| LKML: Junio C Hamano: [ANNOUNCE] Git v2.6.1, v2.5.4, v2.4.10 and v2.3.10 | af854a3a-2127-422b-91ae-364da2661108 | lkml.org | |
| git/2.6.1.txt at master · git/git · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| USN-2835-1: Git vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| git/2.3.10.txt at master · git/git · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Vendor Advisory |
| oss-security - Re: CVE for git issue - please use CVE-2015-7545 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Oracle Linux Bulletin - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Debian -- Security Information -- DSA-3435-1 git | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| git/2.5.4.txt at master · git/git · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Vendor Advisory |
| openSUSE-SU-2015:1968-1: moderate: Security update for git | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Linux Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| 33cfccbbf35a56e190b79bdec5c85457c952a021 - pub/scm/git/git - Git at Google | af854a3a-2127-422b-91ae-364da2661108 | kernel.googlesource.com | |
| oss-security - Re: CVE for git issue - please use CVE-2015-7545 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - CVE for git issue - please use CVE-2015-7545 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Oracle Solaris Bulletin - April 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.