CVE-2014-9706

Loading...

General

Score:7.5/10.0
Severity:High
Category:Input Validation Error

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Relative vulnerabilities

CVE-2015-0838

Published on 31/03/15 - Updated on 15/04/15

Description

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

Category: Input Validation Error

CWE-19 (Data Handling)
Weaknesses in this category are typically found in functionality that processes data.

Security Notices

US National Vulnerability DatabaseCVE-2014-9706
Debian DSA-3206-1

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
debiandebian_linux
dulwich_projectdulwich

Share this vulnerability with:

Twitter Facebook LinkedIn Mail