Git CVE-2017-1000117 Remote Command Injection Vulnerability
BID:100283
CVE-2017-1000117 |Info
Git CVE-2017-1000117 Remote Command Injection Vulnerability
| Bugtraq ID: | 100283 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-1000117 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2017 12:00AM |
| Updated: | Sep 20 2017 04:59PM |
| Credit: | Trevor Jay |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Redhat Software Collections for RHEL 0 Redhat Enterprise Linux Workstation Optional 7 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 7 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 7 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux ComputeNode Optional 7 Redhat Enterprise Linux Client Optional 7 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Oracle Linux 7 openSUSE Leap 42.3 GIT GIT 2.14 GIT GIT 2.13.4 GIT GIT 2.13.3 GIT GIT 2.13.2 GIT GIT 2.13.1 GIT GIT 2.13 GIT GIT 2.12.3 GIT GIT 2.12 GIT GIT 2.11.2 GIT GIT 2.11 GIT GIT 2.10.3 GIT GIT 2.10 GIT GIT 2.9.4 GIT GIT 2.9 GIT GIT 2.8.5 GIT GIT 2.8 GIT GIT 2.7.5 GIT GIT 2.7.1 GIT GIT 2.7 GIT GIT 2.6.7 GIT GIT 2.6.1 GIT GIT 2.6 GIT GIT 2.5.6 GIT GIT 2.5.4 GIT GIT 2.5.3 GIT GIT 2.5.2 GIT GIT 2.5.1 GIT GIT 2.5 GIT GIT 2.4.12 GIT GIT 2.4.10 GIT GIT 2.4.9 GIT GIT 2.4.8 GIT GIT 2.4.7 GIT GIT 2.4.6 GIT GIT 2.4.5 GIT GIT 2.4.4 GIT GIT 2.4.3 GIT GIT 2.4.2 GIT GIT 2.4.1 GIT GIT 2.3.10 GIT GIT 2.3.9 GIT GIT 2.3.8 GIT GIT 2.3.7 GIT GIT 2.3.6 GIT GIT 2.3.5 GIT GIT 2.3.4 GIT GIT 2.3.3 GIT GIT 2.3.2 GIT GIT 2.3.1 GIT GIT 2.3 GIT GIT 2.2.1 GIT GIT 2.2 GIT GIT 2.1.4 GIT GIT 2.1.3 GIT GIT 2.1 GIT GIT 2.0.5 GIT GIT 2.0.4 GIT GIT 2.0 GIT GIT 1.9.5 GIT GIT 1.9.4 GIT GIT 1.9 GIT GIT 1.8.5 6 GIT GIT 1.7.2 GIT GIT 1.6.3 .2 GIT GIT 1.6 6 GIT GIT 1.6 5 GIT GIT 1.5.6 6 GIT GIT 1.5.6 5 GIT GIT 1.5.6 .4 GIT GIT 1.5.6 .3 GIT GIT 1.5.6 GIT GIT 1.5.5 6 GIT GIT 1.5.5 5 GIT GIT 1.5.5 GIT GIT 1.5.4 7 GIT GIT 1.5.4 6 GIT GIT 1.5.2 4 GIT GIT 1.1.5 GIT GIT 1.1.4 GIT GIT 1.8.5.5 GIT GIT 1.8.5.0 GIT GIT 1.8.1.4 GIT GIT 1.8.1.3 GIT GIT 1.8 GIT GIT 1.7.3.4 GIT GIT 1.7.3.3 GIT GIT 1.4.4.5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Atlassian SourceTree for Windows 0.5.1.0 Atlassian SourceTree for macOS 1.0b2 Apple Xcode 7.3.1 Apple Xcode 6.0.1 Apple Xcode 2.4.1 Apple Xcode 8.1 Apple Xcode 8 Apple Xcode 7.3 Apple Xcode 7.2 Apple Xcode 7.1 Apple Xcode 7.0 Apple Xcode 6.3 Apple Xcode 6.2 Apple Xcode 6.0 Apple Xcode 5.0 Apple Xcode 4.4 Apple Xcode 4.3.3 Apple Xcode 4.3.2 Apple Xcode 4.3.1 Apple Xcode 4.3 Apple Xcode 4.2.1 Apple Xcode 4.2 Apple Xcode 4.1.1 Apple Xcode 4.0.2 Apple Xcode 4.0.1 Apple Xcode 3.2.5 Apple Xcode 3.2.4 Apple Xcode 3.2.3 Apple Xcode 3.2.2 Apple Xcode 3.2.1 Apple Xcode 3.1.4 Apple Xcode 3.1.3 Apple Xcode 3.1.2 Apple Xcode 3.1.1 Apple Xcode 3.1 Apple Xcode 3.0 Apple Xcode 2.3 Apple Xcode 2.2 Apple Xcode 2.1 Apple Xcode 2.0 Apple Xcode 1.5 |
| Not Vulnerable: |
GIT GIT 2.14.1 GIT GIT 2.13.5 GIT GIT 2.12.4 GIT GIT 2.11.3 GIT GIT 2.10.4 GIT GIT 2.9.5 GIT GIT 2.8.6 GIT GIT 2.7.6 Atlassian SourceTree for Windows 2.1.10 Atlassian SourceTree for macOS 2.6.1 Apple Xcode 9 |
Discussion
Git CVE-2017-1000117 Remote Command Injection Vulnerability
Git is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
Git is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
Exploit / POC
Git CVE-2017-1000117 Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Git CVE-2017-1000117 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Git CVE-2017-1000117 Remote Command Injection Vulnerability
References:
References:
- [ANNOUNCE] Git v2.14.1, v2.13.5, and others (Junio C Hamano)
- Compromise On Checkout - Vulnerabilities in SCM Tools (Recurity Labs)
- Git Homepage (Git)
- CVE-2017-1000117 git: Command injection via malicious ssh URLs (Red Hat)
- SourceTree Security Advisory 2017-08-11 (Atlassian)