Oval Definition:oval:com.ubuntu.bionic:def:201811235000
Revision Date:2018-05-30Version:1
Title:CVE-2018-11235 on Ubuntu 18.04 LTS (bionic) - high.
Description:In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-11235
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND The 'git' package in bionic was vulnerable but has been fixed (note: '1:2.17.1-1ubuntu0.1').
  • BACK