PT-2009-1073 · Git · Git
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
git versions 1.5.x through 1.5.4
git versions prior to 1.6.0.6
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters related to git search, potentially leading to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely.
Recommendations
For git versions 1.5.x through 1.5.4, update to version 1.5.5 or later.
For git versions prior to 1.6.0.6, update to version 1.6.0.6 or later.
Correção
RCE
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Git