Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.811706
Category:General
Title:Git Remote Code Execution Vulnerability - Windows
Summary:Git is prone to a remote code execution (RCE) vulnerability.
Description:Summary:
Git is prone to a remote code execution (RCE) vulnerability.

Vulnerability Insight:
The flaw exists due to error related to the
handling of 'ssh' URLs.

Vulnerability Impact:
Successful exploitation of this
vulnerability will allow remote attackers to execute arbitrary code on the
affected system.

Affected Software/OS:
Git versions 2.14.x prior to 2.14.1, 2.13.x
prior to 2.13.5, 2.12.x prior to 2.12.4, 2.11.x prior to 2.11.3, 2.10.x prior to
2.10.4, 2.9.x prior to 2.9.5, 2.8.x prior to 2.8.6 and 2.7.x prior to 2.7.6.

Solution:
Upgrade to Git version 2.14.1 or 2.13.5 or
2.12.4 or 2.11.3 or 2.10.4 or 2.9.5 or 2.8.6 or 2.7.6 or newer.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-1000117
BugTraq ID: 100283
http://www.securityfocus.com/bid/100283
Debian Security Information: DSA-3934 (Google Search)
http://www.debian.org/security/2017/dsa-3934
https://www.exploit-db.com/exploits/42599/
https://security.gentoo.org/glsa/201709-10
https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1466490.html
RedHat Security Advisories: RHSA-2017:2484
https://access.redhat.com/errata/RHSA-2017:2484
RedHat Security Advisories: RHSA-2017:2485
https://access.redhat.com/errata/RHSA-2017:2485
RedHat Security Advisories: RHSA-2017:2491
https://access.redhat.com/errata/RHSA-2017:2491
RedHat Security Advisories: RHSA-2017:2674
https://access.redhat.com/errata/RHSA-2017:2674
RedHat Security Advisories: RHSA-2017:2675
https://access.redhat.com/errata/RHSA-2017:2675
http://www.securitytracker.com/id/1039131
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.