VYPR

rpm package

suse/git&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

pkg:rpm/suse/git&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1

Vulnerabilities (11)

  • CVE-2020-11008Apr 21, 2020
    affected < 2.26.2-27.36.1fixed 2.26.2-27.36.1

    Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ cred

  • CVE-2020-5260Apr 14, 2020
    affected < 2.26.0-27.27.1fixed 2.26.0-27.27.1

    Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the o

  • CVE-2018-17456Oct 6, 2018
    affected < 2.12.3-27.17.2fixed 2.12.3-27.17.2

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '

  • CVE-2018-11235May 30, 2018
    affected < 2.12.3-27.14.1fixed 2.12.3-27.14.1

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-subm

  • CVE-2018-11233May 30, 2018
    affected < 2.12.3-27.14.1fixed 2.12.3-27.14.1

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

  • CVE-2017-1000117HigOct 5, 2017
    affected < 2.12.3-27.5.1fixed 2.12.3-27.5.1

    A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an un

  • CVE-2017-14867HigSep 29, 2017
    affected < 2.12.3-27.9.1fixed 2.12.3-27.9.1

    Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The

  • CVE-2017-8386HigJun 1, 2017
    affected < 2.12.3-26.1fixed 2.12.3-26.1

    git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name

  • CVE-2015-7545CriApr 13, 2016
    affected < 1.8.5.6-15.1fixed 1.8.5.6-15.1

    The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in

  • CVE-2016-2324CriApr 8, 2016
    affected < 1.8.5.6-18.1fixed 1.8.5.6-18.1

    Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

  • CVE-2016-2315CriApr 8, 2016
    affected < 1.8.5.6-18.1fixed 1.8.5.6-18.1

    revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.