Oval Definition:oval:com.ubuntu.trusty:def:20171000117000
Revision Date:2017-10-04Version:1
Title:CVE-2017-1000117 on Ubuntu 14.04 LTS (trusty) - medium.
Description:A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone Brian Neel, Joern Schneeweisz, and Jeff King discovered that Git did not properly handle host names in 'ssh://' URLs. A remote attacker could use this to construct a git repository that when accessed could run arbitrary code with the privileges of the user.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-1000117
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND The 'git' package in trusty was vulnerable but has been fixed (note: '1:1.9.1-1ubuntu0.6').
  • BACK