Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:203C69B9D4D62C6B2BB5EF5F1DD2D600
HistoryMar 24, 2016 - 12:00 a.m.

USN-2938-1 Git vulnerabilities | Cloud Foundry

2016-03-2400:00:00
Cloud Foundry
www.cloudfoundry.org
25

0.141 Low

EPSS

Percentile

95.7%

USN-2938-1 Git vulnerabilities

High

Vendor

Ubuntu, Git

Versions Affected

  • All Git versions prior to 2.7.4

Description

Git could be made to crash or run programs as your login if it received changes from a specially crafted remote repository.

Laël Cellier discovered that Git incorrectly handled path strings in crafted Git repositories. A remote attacker could use this issue to cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking Git. (CVE-2016-2315, CVE-2016-2324)

Credit

Laël Cellier

References