ISOMAN

CVE

CVE-2015-7545

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

Severity
CRITICAL
CVSS
9.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-updates/2015-11/msg00066.html
  2. http://rhn.redhat.com/errata/RHSA-2015-2515.html
  3. http://www.debian.org/security/2016/dsa-3435
  4. http://www.openwall.com/lists/oss-security/2015/12/08/5
  5. http://www.openwall.com/lists/oss-security/2015/12/09/8
  6. http://www.openwall.com/lists/oss-security/2015/12/11/7
  7. http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
  8. http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
  9. http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
  10. http://www.securityfocus.com/bid/78711
  11. http://www.securitytracker.com/id/1034501
  12. http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.533255
  13. http://www.ubuntu.com/usn/USN-2835-1
  14. https://bugzilla.redhat.com/show_bug.cgi?id=1269794
  15. https://github.com/git/git/blob/master/Documentation/RelNotes/2.3.10.txt
  16. https://github.com/git/git/blob/master/Documentation/RelNotes/2.4.10.txt
  17. https://github.com/git/git/blob/master/Documentation/RelNotes/2.5.4.txt
  18. https://github.com/git/git/blob/master/Documentation/RelNotes/2.6.1.txt
  19. https://kernel.googlesource.com/pub/scm/git/git/+/33cfccbbf35a56e190b79bdec5c85457c952a021
  20. https://lkml.org/lkml/2015/10/5/683