ISOMAN

CVE

CVE-2017-8386

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-updates/2017-05/msg00090.html
  2. http://public-inbox.org/git/xmqq8tm5ziat.fsf%40gitster.mtv.corp.google.com/
  3. http://www.debian.org/security/2017/dsa-3848
  4. http://www.securityfocus.com/bid/98409
  5. http://www.securitytracker.com/id/1038479
  6. http://www.ubuntu.com/usn/USN-3287-1
  7. https://access.redhat.com/errata/RHSA-2017:2004
  8. https://access.redhat.com/errata/RHSA-2017:2491
  9. https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/
  10. https://kernel.googlesource.com/pub/scm/git/git/+/3ec804490a265f4c418a321428c12f3f18b7eff5
  11. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ISHYFLM2ACYHHY3JHCLF75X7UF4ZMDM/
  12. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPYRN7APMHY4ZFDPAKD22J5R4QJFY2JP/
  13. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDS3LSJJ3YGGQYIVPKQDVOCXWDSF6JGF/
  14. https://security.gentoo.org/glsa/201706-04
  15. http://lists.opensuse.org/opensuse-updates/2017-05/msg00090.html
  16. http://public-inbox.org/git/xmqq8tm5ziat.fsf%40gitster.mtv.corp.google.com/
  17. http://www.debian.org/security/2017/dsa-3848
  18. http://www.securityfocus.com/bid/98409
  19. http://www.securitytracker.com/id/1038479
  20. http://www.ubuntu.com/usn/USN-3287-1