CVE Vulnerabilities

CVE-2017-16228

Published: Oct 29, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.

Affected Software

NameVendorStart VersionEnd Version
DulwichDulwich_project*0.18.4 (including)
DulwichUbuntuartful*
DulwichUbuntuesm-apps/xenial*
DulwichUbuntutrusty*
DulwichUbuntuupstream*
DulwichUbuntuxenial*
DulwichUbuntuzesty*

References