CVE Feed

    Dashboard / CVE / CVE-2014-9390

    CVE-2014-9390

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

    Published:Dec 18, 2014
    Last Modified:Nov 21, 2024
    EPS:Feb 12, 2020
    EPSS Score:0.53354
    CVSS Score:9.8

    Affected Products

    Vendor
    Apple
    Product
    Mac Os X
    Vendor
    Apple
    Product
    Xcode
    Vendor
    Eclipse
    Product
    Egit
    Vendor
    Eclipse
    Product
    Jgit
    Vendor
    Git-scm
    Product
    Git
    Vendor
    Libgit2
    Product
    Libgit2
    Vendor
    Mercurial
    Product
    Mercurial
    Vendor
    Microsoft
    Product
    Windows

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High