PT-2018-5685 · Mozilla+2 · Mercurial+2

Zhang Tianqi

·

Published

2018-01-26

·

Updated

2019-10-03

·

CVE-2017-14593

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sourcetree for Windows versions 0.5.1.0 through 2.4.7.0 (excluding 2.4.7.0)
Description: The issue affects the handling of Mercurial and Git repositories in Sourcetree for Windows, allowing an attacker with commit permission to a linked repository to exploit argument and command injection bugs and gain code execution on the system. This vulnerability can be triggered from a webpage using the Sourcetree URI handler, starting from version 0.8.4b.
Recommendations: For versions 0.5.1.0 through 2.4.7.0 (excluding 2.4.7.0), update to version 2.4.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Sourcetree URI handler and limiting commit permissions to repositories.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14593

Affected Products

Git
Mercurial
Sourcetree For Windows