CVE-2022-39260
published 2022-10-19CVE-2022-39260: Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull…
PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.94%
85.6th percentile
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shell` as a login shell in order to be vulnerable to this attack. This problem is patched in versions 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 and users are advised to upgrade to the latest version. Disabling `git shell` access via remote logins is a viable short-term workaround.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 14.1 | 14.1 |
| apple | xcode | — | — |
| debian | debian_linux | — | — |
| debian | git | < git 1:2.38.1-1 (bookworm) | git 1:2.38.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| git-scm | git | < 2.30.6 | 2.30.6 |
| git-scm | git | — | — |
| git-scm | git | >= 2.31.0 < 2.31.5 | 2.31.5 |
| git-scm | git | >= 2.32.0 < 2.32.4 | 2.32.4 |
| git-scm | git | >= 2.33.0 < 2.33.5 | 2.33.5 |
| git-scm | git | >= 2.34.0 < 2.34.5 | 2.34.5 |
| git-scm | git | >= 2.35.0 < 2.35.5 | 2.35.5 |
| git-scm | git | >= 2.36.0 < 2.36.3 | 2.36.3 |
| git-scm | git | >= 2.37.0 < 2.37.4 | 2.37.4 |
| git | git | < 2.30.6 | 2.30.6 |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | >= 0 < 1:2.30.2-1+deb11u1 | 1:2.30.2-1+deb11u1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
git vulnerability
osv·2022-11-17·CVSS 8.8
CVE-2022-39260 [HIGH] git vulnerability
git vulnerability
USN-5686-1 fixed several vulnerabilities in Git. This update
provides the corresponding fix for CVE-2022-39260 on Ubuntu 16.04 ESM.
Original advisory details:
Kevin Backhouse discovered that Git incorrectly handled certain command
strings. An attacker could possibly use this issue to cause a crash or
arbitrary code execution.
OSV
CVE-2022-39260: Git is an open source, scalable, distributed revision control system
osv·2022-10-19·CVSS 8.8
CVE-2022-39260 [HIGH] CVE-2022-39260: Git is an open source, scalable, distributed revision control system
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shell` as a login shell in order to be vulnerable to this attack. This problem is patched in v
OSV
git vulnerabilities
osv·2022-10-18·CVSS 5.5
CVE-2022-39253 [MEDIUM] git vulnerabilities
git vulnerabilities
Cory Snider discovered that Git incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause an unexpected behaviour.
(CVE-2022-39253)
Kevin Backhouse discovered that Git incorrectly handled certain command strings.
An attacker could possibly use this issue to arbitrary code execution.
(CVE-2022-39260)
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Git vulnerabilities
vendor_ubuntu·2022-11-21·CVSS 5.5
CVE-2022-39260 [MEDIUM] Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
USN-5686-1 fixed vulnerabilities in Git. This update provides the corresponding
updates for Ubuntu 22.10.
Original advisory details:
Cory Snider discovered that Git incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause an unexpected behaviour.
(CVE-2022-39253)
Kevin Backhouse discovered that Git incorrectly handled certain command strings.
An attacker could possibly use this issue to arbitrary code execution.
(CVE-2022-39260)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Git vulnerability
vendor_ubuntu·2022-11-17·CVSS 8.5
CVE-2022-39260 [HIGH] Git vulnerability
Title: Git vulnerability
Summary: Git could be made to crash or run programs as your login if it
received specially crafted input.
USN-5686-1 fixed several vulnerabilities in Git. This update
provides the corresponding fix for CVE-2022-39260 on Ubuntu 16.04 ESM.
Original advisory details:
Kevin Backhouse discovered that Git incorrectly handled certain command
strings. An attacker could possibly use this issue to cause a crash or
arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2022-39260: Xcode 14.1
vendor_apple·2022-11-01·CVSS 8.5
CVE-2022-39260 [HIGH] CVE-2022-39260: Xcode 14.1
Apple Security Update: About the security content of Xcode 14.1
Product: Xcode
Version: 14.1
CVE: CVE-2022-39260
Component: Git
Impact: A remote user may cause an unexpected app termination or arbitrary code execution if git shell is allowed as a login shell
Description: This issue was addressed with improved checks.
Red Hat
git: git shell function that splits command arguments can lead to arbitrary heap writes.
vendor_redhat·2022-10-18·CVSS 8.5
CVE-2022-39260 [HIGH] CWE-787 git: git shell function that splits command arguments can lead to arbitrary heap writes.
git: git shell function that splits command arguments can lead to arbitrary heap writes.
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shel
Ubuntu
Git vulnerabilities
vendor_ubuntu·2022-10-18·CVSS 5.5
CVE-2022-39260 [MEDIUM] Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Cory Snider discovered that Git incorrectly handled certain symbolic links.
An attacker could possibly use this issue to cause an unexpected behaviour.
(CVE-2022-39253)
Kevin Backhouse discovered that Git incorrectly handled certain command strings.
An attacker could possibly use this issue to arbitrary code execution.
(CVE-2022-39260)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-39260: git - Git is an open source, scalable, distributed revision control system. `git shell...
vendor_debian·2022·CVSS 8.5
CVE-2022-39260 [HIGH] CVE-2022-39260: git - Git is an open source, scalable, distributed revision control system. `git shell...
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shell` as a login shell in order to be vulnerable to this attack. This problem is patched in v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Nov/1https://github.com/git/git/security/advisories/GHSA-rjr6-wcq6-83p6https://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7B6JPKX5CGGLAHXJVQMIZNNEEB72FHD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHNO2FB55CPX47BAXMBWUBGWHO6N6ZZH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKFHE4KVD7EKS5J3KTDFVBEKU3CLXGVV/https://security.gentoo.org/glsa/202312-15https://support.apple.com/kb/HT213496http://seclists.org/fulldisclosure/2022/Nov/1https://github.com/git/git/security/advisories/GHSA-rjr6-wcq6-83p6https://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7B6JPKX5CGGLAHXJVQMIZNNEEB72FHD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OHNO2FB55CPX47BAXMBWUBGWHO6N6ZZH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UKFHE4KVD7EKS5J3KTDFVBEKU3CLXGVV/https://security.gentoo.org/glsa/202312-15https://support.apple.com/kb/HT213496
2022-10-19
Published