Vulnerability Description
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Git-Scm | Git | <= 2.10.4 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2017/09/26/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/101060Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039431Third Party AdvisoryVDB Entry
- https://bugs.debian.org/876854Issue TrackingMailing ListThird Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00246.htmlMailing ListThird Party Advisory
- https://public-inbox.org/git/xmqqy3p29ekj.fsf%40gitster.mtv.corp.google.com/T/#u
- https://www.debian.org/security/2017/dsa-3984Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/09/26/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/101060Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039431Third Party AdvisoryVDB Entry
- https://bugs.debian.org/876854Issue TrackingMailing ListThird Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00246.htmlMailing ListThird Party Advisory
- https://public-inbox.org/git/xmqqy3p29ekj.fsf%40gitster.mtv.corp.google.com/T/#u
- https://www.debian.org/security/2017/dsa-3984Third Party Advisory
FAQ
What is CVE-2017-14867?
CVE-2017-14867 is a vulnerability with a CVSS score of 8.8 (HIGH). Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers ...
How severe is CVE-2017-14867?
CVE-2017-14867 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14867?
Check the references section above for vendor advisories and patch information. Affected products include: Git-Scm Git, Debian Debian Linux.