First published: Fri May 12 2017(Updated: )
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/git | <2.4.12 | 2.4.12 |
redhat/git | <2.5.6 | 2.5.6 |
redhat/git | <2.6.7 | 2.6.7 |
redhat/git | <2.7.5 | 2.7.5 |
redhat/git | <2.8.5 | 2.8.5 |
redhat/git | <2.9.4 | 2.9.4 |
redhat/git | <2.10.3 | 2.10.3 |
redhat/git | <2.11.2 | 2.11.2 |
redhat/git | <2.12.3 | 2.12.3 |
Git Git-shell | ||
openSUSE Leap | =42.1 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =16.10 | |
Canonical Ubuntu Linux | =17.04 | |
Fedoraproject Fedora | =24 | |
Fedoraproject Fedora | =25 | |
Fedoraproject Fedora | =26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.