UBUNTU-CVE-2017-1000117
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-1000117
UBUNTU-CVE-2017-1000117
Summary:
Details: A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
References: https://ubuntu.com/security/CVE-2017-1000117, http://marc.info/?l=git&m=150238802328673&w=2, https://ubuntu.com/security/notices/USN-3387-1, https://www.cve.org/CVERecord?id=CVE-2017-1000117
Affected packages
Package
Name: git
Purl: pkg:deb/ubuntu/git@1:1.9.1-1ubuntu0.6?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
