Vulnerability Name:

CVE-2017-14176 (CCN-135732)

Assigned:2017-08-15
Published:2017-08-15
Updated:2019-10-03
Summary:Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Bazaar Web page
Viewing all changes in revision 6754

Source: MITRE
Type: CNA
CVE-2017-14176

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14176.html

Source: CCN
Type: IBM Security Bulletin 716653 (Cloud Private)
Multiple Security Vulnerabilities affect IBM Cloud Private

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
http://www.ubuntu.com/usn/usn-3411-1

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugs.debian.org/874429

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugs.launchpad.net/bzr/+bug/1710979

Source: CCN
Type: Red Hat Bugzilla – Bug 1486685
(CVE-2017-14176) CVE-2017-14176 bzr: does not strip bzr+ssh SSH options

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1486685

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1058214

Source: XF
Type: UNKNOWN
bazaar-cve201714176-cmd-exec(135732)

Source: DEBIAN
Type: Issue Tracking, Third Party Advisory
DSA-4052

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-14176

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:canonical:bazaar:*:*:*:*:*:*:*:* (Version <= 2.7.0)

  • Configuration CCN 1:
  • cpe:/a:canonical:bazaar:2.7.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714176
    V
    CVE-2017-14176
    2022-05-20
    oval:org.opensuse.security:def:27217
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26599
    P
    libpython2_6-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27363
    P
    PackageKit-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26929
    P
    kdenetwork4-filesharing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27266
    P
    perl-libwww-perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26663
    P
    PolicyKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28001
    P
    Security update for SDL_image (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27013
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26587
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27305
    P
    taglib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26791
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28036
    P
    Security update for bzr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27164
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26588
    P
    libicu-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27319
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26872
    P
    cifs-utils on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:201714176000
    V
    CVE-2017-14176 on Ubuntu 17.10 (artful) - medium.
    2017-11-27
    oval:com.ubuntu.xenial:def:2017141760000000
    V
    CVE-2017-14176 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-11-27
    oval:com.ubuntu.trusty:def:201714176000
    V
    CVE-2017-14176 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-11-27
    oval:com.ubuntu.xenial:def:201714176000
    V
    CVE-2017-14176 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-11-27
    BACK
    debian debian linux 8.0
    debian debian linux 9.0
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.04
    canonical bazaar *
    canonical bazaar 2.7.0
    ibm cloud private 2.1.0