Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
BID:105523
CVE-2018-17456 |Info
Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 105523 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-17456 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2018 12:00AM |
| Updated: | Oct 05 2018 12:00AM |
| Credit: | joernchen and Jeff King. |
| Vulnerable: |
Redhat OpenShift Enterprise 3.10 Redhat OpenShift Container Platform 3.9 Redhat OpenShift Container Platform 3.7 Redhat Enterprise Linux 7 GIT GIT 2.19 GIT GIT 2.18 GIT GIT 2.17.1 GIT GIT 2.17 GIT GIT 2.16.4 GIT GIT 2.16.3 GIT GIT 2.16 GIT GIT 2.15.2 GIT GIT 2.15.1 GIT GIT 2.15 GIT GIT 2.14.4 GIT GIT 2.14.3 GIT GIT 2.14.2 GIT GIT 2.14.1 GIT GIT 2.14 GIT GIT 2.13.6 GIT GIT 2.13.5 GIT GIT 2.13.4 GIT GIT 2.13.3 GIT GIT 2.13.2 GIT GIT 2.13.1 GIT GIT 2.13 |
| Not Vulnerable: |
GIT GIT 2.19.1 GIT GIT 2.18.1 GIT GIT 2.17.2 GIT GIT 2.16.5 GIT GIT 2.15.3 GIT GIT 2.14.5 |
Discussion
Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
Git is prone to an arbitrary code-execution vulnerability.
A remote attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
Git versions prior to 2.14.5, 2.15.3, 2.16.5, 2.17.2, 2.18.1, and 2.19.1 are vulnerable.
Git is prone to an arbitrary code-execution vulnerability.
A remote attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
Git versions prior to 2.14.5, 2.15.3, 2.16.5, 2.17.2, 2.18.1, and 2.19.1 are vulnerable.
Exploit / POC
Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Git CVE-2018-17456 Arbitrary Code Execution Vulnerability
References:
References:
- Bug 1110949 - (CVE-2018-17456) VUL-0: CVE-2018-17456: git,libgit2: arbitrary cod (SuSE)
- Git Homepage (Git)
- Bug 1636619 - (CVE-2018-17456) CVE-2018-17456 git: arbitrary code execution via (Red Hat Bugzilla)
- CVE-2018-17456 (Red Hat Bugzilla)