[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-9390Date: (C)2020-02-13   (M)2023-12-22


Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.8CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
http://article.gmane.org/gmane.linux.kernel/1853266
http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html
http://mercurial.selenic.com/wiki/WhatsNew
http://securitytracker.com/id?1031404
http://support.apple.com/kb/HT204147
https://github.com/blog/1938-git-client-vulnerability-announced
https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915
https://libgit2.org/security/
https://news.ycombinator.com/item?id=8769667

CPE    4
cpe:/o:apple:mac_os_x:-
cpe:/a:apple:xcode
cpe:/a:mercurial:mercurial
cpe:/o:microsoft:windows:-
...
CWE    1
CWE-20
OVAL    8
oval:org.secpod.oval:def:602086
oval:org.secpod.oval:def:52385
oval:org.secpod.oval:def:22311
oval:org.secpod.oval:def:22310
...

© SecPod Technologies