cbcvebase.
CVE-2017-12976
published 2017-08-20

CVE-2017-12976: git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as…

PriorityP350high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.67%
84.3th percentile
git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalbazaar<= 2.7.0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbreezy< breezy 3.0.0~bzr6772-1 (bookworm)breezy 3.0.0~bzr6772-1 (bookworm)
debianbzr< breezy 3.0.0~bzr6772-1 (bookworm)breezy 3.0.0~bzr6772-1 (bookworm)
debianbzr0 – 2.7.0
debiandebian_linux
debiandebian_linux
debiandulwich< dulwich 0.18.5-1 (bookworm)dulwich 0.18.5-1 (bookworm)
debianfossil< fossil 1:2.4-1 (bookworm)fossil 1:2.4-1 (bookworm)
debiangit-annex< git-annex 6.20170818-1 (bookworm)git-annex 6.20170818-1 (bookworm)
dulwich_projectdulwich<= 0.18.4
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.5-10.18.5-1
dulwich_projectdulwich>= 0 < 0.18.50.18.5
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil-scmfossil>= 0 < 1:2.4-11:2.4-1
fossil_scmfossil< 2.42.4
git-annex_projectgit-annex<= 6.20170520
git-annex_projectgit-annex>= 0 < 6.20170818-16.20170818-1
git-annex_projectgit-annex>= 0 < 6.20170818-16.20170818-1

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.