CVE-2018-11233
published 2018-05-30CVE-2018-11233: In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.31%
90.1th percentile
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | git | < git 1:2.17.1-1 (bookworm) | git 1:2.17.1-1 (bookworm) |
| git-scm | git | <= 2.13.6 | — |
| git-scm | git | — | — |
| git-scm | git | 2.14.0 – 2.14.3 | — |
| git-scm | git | 2.15.0 – 2.15.1 | — |
| git-scm | git | 2.16.0 – 2.16.3 | — |
| git | git | >= 0 < 1:2.17.1-1 | 1:2.17.1-1 |
| git | git | >= 0 < 1:2.17.1-1 | 1:2.17.1-1 |
| git | git | >= 0 < 1:2.17.1-1 | 1:2.17.1-1 |
| git | git | >= 0 < 1:2.17.1-1 | 1:2.17.1-1 |
| git | git | >= 0 < 1:1.9.1-1ubuntu0.8 | 1:1.9.1-1ubuntu0.8 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.4 | 1:2.7.4-0ubuntu1.4 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.1 | 1:2.17.1-1ubuntu0.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-11233: Xcode 9.4.1
vendor_apple·2018-06-13·CVSS 7.5
CVE-2018-11233 [HIGH] CVE-2018-11233: Xcode 9.4.1
Apple Security Update: About the security content of Xcode 9.4.1
Product: Xcode
Version: 9.4.1
CVE: CVE-2018-11233
Component: CVE-2018-11233
Ubuntu
Git vulnerabilities
vendor_ubuntu·2018-06-05·CVSS 7.5
CVE-2018-11233 [HIGH] Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Etienne Stalmans discovered that git did not properly validate git
submodules files. A remote attacker could possibly use this to craft a
git repo that causes arbitrary code execution when "git clone
--recurse-submodules" is used. (CVE-2018-11235)
It was discovered that an integer overflow existed in git's pathname
consistency checking code when used on NTFS filesystems. An attacker could
use this to cause a denial of service or expose sensitive information.
(CVE-2018-11233)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
vendor_redhat·2018-05-30·CVSS 7.5
CVE-2018-11233 [HIGH] CWE-20 git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
Statement: This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.
Package: jgit (JBoss Developer Studio 11) - Will not fix
Package: git (Red Hat Enterprise Linux 6) - Not affected
Package: git (Red Hat Enterprise Linux 7) - Not affected
Package: git (Red Hat Enterprise Linux 8) - Not affected
Package: camel (Red Hat Fuse 7) - Not affected
Package: jgit (Red Hat JBoss A-MQ 6) - Not affected
Package: jgit (Red Hat JBoss BRMS 6) - Not affe
Debian
CVE-2018-11233: git - In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before ...
vendor_debian·2018·CVSS 7.5
CVE-2018-11233 [HIGH] CVE-2018-11233: git - In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before ...
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
Scope: local
bookworm: resolved (fixed in 1:2.17.1-1)
bullseye: resolved (fixed in 1:2.17.1-1)
forky: resolved (fixed in 1:2.17.1-1)
sid: resolved (fixed in 1:2.17.1-1)
trixie: resolved (fixed in 1:2.17.1-1)
GHSA
GHSA-f2cx-gr8r-v8wf: In Git before 2
ghsa_unreviewed·2022-05-13
CVE-2018-11233 [HIGH] CWE-125 GHSA-f2cx-gr8r-v8wf: In Git before 2
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
OSV
git vulnerabilities
osv·2018-06-05·CVSS 7.5
CVE-2018-11235 [HIGH] git vulnerabilities
git vulnerabilities
Etienne Stalmans discovered that git did not properly validate git
submodules files. A remote attacker could possibly use this to craft a
git repo that causes arbitrary code execution when "git clone
--recurse-submodules" is used. (CVE-2018-11235)
It was discovered that an integer overflow existed in git's pathname
consistency checking code when used on NTFS filesystems. An attacker could
use this to cause a denial of service or expose sensitive information.
(CVE-2018-11233)
OSV
CVE-2018-11233: In Git before 2
osv·2018-05-30·CVSS 7.5
CVE-2018-11233 [HIGH] CVE-2018-11233: In Git before 2
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11233 git: path sanity-checks on NTFS can read arbitrary memory [fedora-all]
bugzilla·2018-05-30·CVSS 7.5
CVE-2018-11233 [HIGH] CVE-2018-11233 git: path sanity-checks on NTFS can read arbitrary memory [fedora-all]
CVE-2018-11233 git: path sanity-checks on NTFS can read arbitrary memory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-11233 git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
bugzilla·2018-05-30·CVSS 7.5
CVE-2018-11233 [HIGH] CVE-2018-11233 git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
CVE-2018-11233 git: path sanity check in is_ntfs_dotgit() can read arbitrary memory
Git before versions 2.13.7, 2.14.4, 2.15.2, 2.16.4 and 2.17.1 performs path
sanity-checks in is_ntfs_dotgit():path.c that can be fooled into reading
arbitrary memory.
Upstream announcement:
https://marc.info/?l=git&m=152761328506724&w=2
Discussion:
Created git tracking bugs for this issue:
Affects: fedora-all [bug 1583890]
---
Statement:
This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.
---
git-2.17.1-2.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.
---
Patch:
https://github.com/git/git/commit/11a9f4d807a0d71dc6eff51bb87baf4ca2c
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttp://www.securityfocus.com/bid/104346http://www.securitytracker.com/id/1040991https://access.redhat.com/errata/RHSA-2018:2147https://marc.info/?l=git&m=152761328506724&w=2https://security.gentoo.org/glsa/201805-13https://usn.ubuntu.com/3671-1/http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttp://www.securityfocus.com/bid/104346http://www.securitytracker.com/id/1040991https://access.redhat.com/errata/RHSA-2018:2147https://marc.info/?l=git&m=152761328506724&w=2https://security.gentoo.org/glsa/201805-13https://usn.ubuntu.com/3671-1/
2018-05-30
Published