Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5347
HistoryOct 30, 2017 - 12:47 a.m.

Arbitrary Command Execution

2017-10-3000:47:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.552 Medium

EPSS

Percentile

97.7%

Dulwich is vulnerable to arbitrary command execution. When using the SSH subprocess, an attacker can use an ssh URL with the - dash character in the hostname.This is related to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.

CPENameOperatorVersion
dulwichle0.18.4