PT-2013-1195 · Git+3 · Git+3

Jan Lieskovsky

·

Published

2013-03-04

·

Updated

2021-01-26

·

CVE-2013-0308

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions git versions 1.7.1 git-all versions 1.7.1 git-cvs versions 1.7.1 git-daemon versions 1.7.1 git-debuginfo versions 1.7.1 git-email versions 1.7.1 git-gui versions 1.7.1 git-svn versions 1.7.1 git-web versions 1.7.1 gitk versions 1.7.1
Description The issue is related to the git package and its various components, which can lead to a violation of protected information integrity. The vulnerability can be exploited remotely. The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, allowing man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Recommendations For git versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-all versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-cvs versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-daemon versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-debuginfo versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-email versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-gui versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-svn versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For git-web versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue. For gitk versions 1.7.1, update to a version later than 1.8.1.4 to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07724
BDU:2015-07725
BDU:2015-07726
BDU:2015-07727
BDU:2015-07728
BDU:2015-07729
BDU:2015-07730
BDU:2015-07731
BDU:2015-07732
BDU:2015-07733
BDU:2015-08968
BDU:2015-08969
BDU:2015-08970
BDU:2015-08971
BDU:2015-08972
BDU:2015-08973
BDU:2015-08974
BDU:2015-08975
BDU:2015-08976
BDU:2015-08977
CESA-2013_0589
CVE-2013-0308
RHSA-2013:0589
RHSA-2013_0589
SUSE-SU-2013_0520-1

Affected Products

Centos
Red Hat
Suse
Git