CVE-2017-16228
Last modified
CVE-2017-16228 is a vulnerability of currently unknown severity. Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.. EPSS estimates a 3.39% chance of exploitation in the next 30 days.
Description
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dulwich Project | Dulwich | <= 0.18.4 |
References
- https://tracker.debian.org/news/882440Issue Tracking, Third Party Advisory
- https://www.dulwich.io/code/dulwich/Product, Vendor Advisory
- https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/Issue Tracking, Patch, Vendor Advisory
- https://tracker.debian.org/news/882440Issue Tracking, Third Party Advisory
- https://www.dulwich.io/code/dulwich/Product, Vendor Advisory
- https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16228?
How severe is CVE-2017-16228?
How do I fix CVE-2017-16228?
Are you affected by CVE-2017-16228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
