PT-2009-1074 · Git · Git

Sebastian Krahmer

·

Published

2009-01-13

·

Updated

2023-02-13

·

CVE-2008-5517

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions git versions 1.5.x through 1.5.5 git versions prior to 1.6.0.6
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters. Multiple vulnerabilities in the git package can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely.
Recommendations For git versions 1.5.x through 1.5.5, update to version 1.5.6 or later. For git versions prior to 1.6.0.6, update to version 1.6.0.6 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2015-09370
CVE-2008-5517
DSA-1708-1

Affected Products

Git