CVE-2014-9938
20.03.2017, 00:59
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| git-scm | git | 𝑥 < 1.9.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| emacs-git |
| ||
| emacs-git-el |
| ||
| git |
| ||
| git-all |
| ||
| git-bzr |
| ||
| git-cvs |
| ||
| git-daemon |
| ||
| git-email |
| ||
| git-gui |
| ||
| git-hg |
| ||
| git-p4 |
| ||
| git-svn |
| ||
| gitk |
| ||
| gitweb |
| ||
| perl-Git |
| ||
| perl-Git-SVN |
|
References