Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Git-scm
Subscribe
|
Git
Subscribe
|
|
Redhat
Subscribe
|
Ansible Tower
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Rhel Software Collections
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4311-1 | git security update |
Ubuntu USN |
USN-3791-1 | Git vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:47:04.938Z
Reserved: 2018-09-25T00:00:00.000Z
Link: CVE-2018-17456
No data.
Status : Modified
Published: 2018-10-06T14:29:00.300
Modified: 2024-11-21T03:54:27.660
Link: CVE-2018-17456
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN