CVE-2018-17456
Last modified
CVE-2018-17456 is a vulnerability of currently unknown severity. Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.. EPSS estimates a 97.36% chance of exploitation in the next 30 days.
Description
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Git-Scm | Git | >= 2.14.0, < 2.14.5 |
| Git-Scm | Git | >= 2.15.0, < 2.15.3 |
| Git-Scm | Git | >= 2.16.0, < 2.16.5 |
| Git-Scm | Git | >= 2.17.0, < 2.17.2 |
| Git-Scm | Git | >= 2.18.0, < 2.18.1 |
| Git-Scm | Git | >= 2.19.0, < 2.19.1 |
| Redhat | Ansible Tower | 3.3 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 6.7 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 7.3 |
| Redhat | Enterprise Linux | 7.4 |
| Redhat | Enterprise Linux | 7.5 |
| Redhat | Enterprise Linux | 7.6 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Debian | Debian Linux | 9.0 |
References
- http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105523Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107511Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041811Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3408Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3541Third Party Advisory
- https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404Patch, Third Party Advisory
- https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46Patch, Third Party Advisory
- https://marc.info/?l=git&m=153875888916397&w=2Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/30Mailing List, Third Party Advisory
- https://usn.ubuntu.com/3791-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4311Third Party Advisory
- https://www.exploit-db.com/exploits/45548/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45631/Exploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2018/10/06/3Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105523Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107511Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041811Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3408Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3541Third Party Advisory
- https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404Patch, Third Party Advisory
- https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46Patch, Third Party Advisory
- https://marc.info/?l=git&m=153875888916397&w=2Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/30Mailing List, Third Party Advisory
- https://usn.ubuntu.com/3791-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4311Third Party Advisory
- https://www.exploit-db.com/exploits/45548/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45631/Exploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2018/10/06/3Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-17456?
How severe is CVE-2018-17456?
How do I fix CVE-2018-17456?
Are you affected by CVE-2018-17456?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
