CVE-2017-14176: Command Injection
Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands
Other sources
It was discovered that the bzr did not properly filter bzr+ssh: URLs, which can be exploited to inject commands via malicious URLs.
Upstream bug: https://bugs.launchpad.net/bzr/+bug/1710979
Patch: http://bazaar.launchpad.net/~brz/brz/trunk/revision/6754
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14176?
CVE-2017-14176 has been classified as a high severity vulnerability due to its capability of allowing remote command execution.
How do I fix CVE-2017-14176?
To address CVE-2017-14176, you should upgrade to affected software versions, such as bzr 2.7.0 or later.
Who is affected by CVE-2017-14176?
CVE-2017-14176 affects users of Bazaar versions up to 2.7.0 that utilize Subprocess SSH.
What type of vulnerability is CVE-2017-14176?
CVE-2017-14176 is a remote command execution vulnerability that can be exploited through specially crafted bzr+ssh URLs.
Can CVE-2017-14176 impact automated deployment systems?
Yes, CVE-2017-14176 could pose a risk to automated deployment systems using vulnerable versions of Bazaar with Subprocess SSH.