CVE Vulnerabilities

CVE-2017-12836

Published: Aug 24, 2017 | Modified: Oct 03, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by -oProxyCommand=id;localhost:/bar.

Affected Software

Name Vendor Start Version End Version
Cvs Gnu 1.12.1 (including) 1.12.1 (including)
Cvs Gnu 1.12.3 (including) 1.12.3 (including)
Cvs Gnu 1.12.5 (including) 1.12.5 (including)
Cvs Gnu 1.12.6 (including) 1.12.6 (including)
Cvs Gnu 1.12.7 (including) 1.12.7 (including)
Cvs Gnu 1.12.9 (including) 1.12.9 (including)
Cvs Gnu 1.12.10 (including) 1.12.10 (including)
Cvs Gnu 1.12.11 (including) 1.12.11 (including)
Cvs Gnu 1.12.12 (including) 1.12.12 (including)
Cvs Gnu 1.12.13 (including) 1.12.13 (including)
Cvs Ubuntu trusty *
Cvs Ubuntu upstream *
Cvs Ubuntu xenial *
Cvs Ubuntu zesty *

References