CVE-2017-16228
Last modified
CVE-2017-16228 is a vulnerability of currently unknown severity. Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.. EPSS estimates a 3.39% chance of exploitation in the next 30 days.
Description
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dulwich Project | Dulwich | <= 0.18.4 |
References
- https://tracker.debian.org/news/882440Issue Tracking, Third Party Advisory
- https://www.dulwich.io/code/dulwich/Product, Vendor Advisory
- https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/Issue Tracking, Patch, Vendor Advisory
- https://tracker.debian.org/news/882440Issue Tracking, Third Party Advisory
- https://www.dulwich.io/code/dulwich/Product, Vendor Advisory
- https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16228?
How severe is CVE-2017-16228?
How do I fix CVE-2017-16228?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16222elding is a simple web server. elding is vulnerable to a dir…
- CVE-2017-16223nodeaaaaa is a static file server. nodeaaaaa is vulnerable t…
- CVE-2017-16224st is a module for serving static files. An attacker is able…
- CVE-2017-16225aegir is a module to help automate JavaScript project manage…
- CVE-2017-16226The static-eval module is intended to evaluate statically-an…
- CVE-2017-16227The aspath_put function in bgpd/bgp_aspath.c in Quagga befor…
- CVE-2017-16229In the Ox gem 2.8.1 for Ruby, the process crashes with a sta…
- CVE-2017-1623IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting…
- CVE-2017-16230In admin/write-post.php in Typecho through 1.1, one can log …
- CVE-2017-16231In PCRE 8.41, after compiling, a pcretest load test PoC prod…5.5
- CVE-2017-16232LibTIFF 4.0.8 has multiple memory leak vulnerabilities, whic…
- CVE-2017-16237In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file…
Are you affected by CVE-2017-16228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
