Git 'contrib/completion/git-prompt.sh' Arbitrary Command Execution Vulnerability
BID:103198
Info
Git 'contrib/completion/git-prompt.sh' Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 103198 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9938 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2017 12:00AM |
| Updated: | Mar 19 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Server - Extended Update Support 7.4 Redhat Enterprise Linux Server - AUS 7.4 Redhat Enterprise Linux Server - 4 Year Extended Update Support 7.4 Redhat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support 7.4 Redhat Enterprise Linux Server 7 Redhat Enterprise Linux for Scientific Computing 7 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.4 Redhat Enterprise Linux for Power, little endian 7 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.4 Redhat Enterprise Linux for Power, big endian 7 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.4 Redhat Enterprise Linux for IBM z Systems 7 Redhat Enterprise Linux EUS Compute Node 7.4 Redhat Enterprise Linux Desktop 7 GIT GIT 1.9.2 GIT GIT 1.9 GIT GIT 1.8.5 6 GIT GIT 1.7.2 GIT GIT 1.6.3 .2 GIT GIT 1.6 6 GIT GIT 1.6 5 GIT GIT 1.5.6 6 GIT GIT 1.5.6 5 GIT GIT 1.5.6 .4 GIT GIT 1.5.6 .3 GIT GIT 1.5.6 GIT GIT 1.5.5 6 GIT GIT 1.5.5 5 GIT GIT 1.5.5 GIT GIT 1.5.4 7 GIT GIT 1.5.4 6 GIT GIT 1.5.2 4 GIT GIT 1.1.5 GIT GIT 1.1.4 GIT GIT 1.8.5.5 GIT GIT 1.8.5.0 GIT GIT 1.8.1.4 GIT GIT 1.8.1.3 GIT GIT 1.8 GIT GIT 1.7.3.4 GIT GIT 1.7.3.3 GIT GIT 1.4.4.5 |
| Not Vulnerable: |
GIT GIT 1.9.3 |
References
Git 'contrib/completion/git-prompt.sh' Arbitrary Command Execution Vulnerability
References:
References:
- Bug 1434415 - (CVE-2014-9938) CVE-2014-9938 git: git-prompt.sh does not sanitize (Red Hat Bugzilla)
- CVE-2014-9938 (Red Hat Bugzilla)
- Git Homepage (Git)
- git-prompt.sh: don't put unsanitized branch names in $PS1 (Github)
- RHSA-2017:2004 - Security Advisory (Redhat)