CVE-2017-14176Command Injection in Bazaar

CWE-77Command Injection15 documents9 sources
Severity
8.8HIGHNVD
CNA9.8OSV9.8
EPSS
1.8%
top 17.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMay 13

Description

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDcanonical/bazaar2.7.0
Debianfossil-scm/fossil< 1:2.4-1+2

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

Patches

🔴Vulnerability Details

6
GHSA
GHSA-jjxg-hpm7-g95f: Bazaar through 22022-05-13
GHSA
GHSA-ff3p-f5xw-q723: http_transport2022-05-13
CVEList
CVE-2017-17459: http_transport2017-12-07
OSV
CVE-2017-17459: http_transport2017-12-07
OSV
CVE-2017-14176: Bazaar through 22017-11-27

📋Vendor Advisories

5
Microsoft
Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands2017-11-14
Ubuntu
Bazaar vulnerability2017-10-24
Red Hat
bzr: does not strip bzr+ssh SSH options2017-08-26
Debian
CVE-2017-14176: breezy - Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to ex...2017
Debian
CVE-2017-17459: fossil - http_transport.c in Fossil before 2.4, when the SSH sync protocol is used, allow...2017

💬Community

2
Bugzilla
CVE-2017-14176 bzr: does not strip bzr+ssh SSH options2017-08-30
Bugzilla
CVE-2017-14176 bzr: does not strip bzr+ssh SSH options [fedora-all]2017-08-30
CVE-2017-14176 — Command Injection in Canonical Bazaar | cvebase