CVE-2017-14176
HIGH8.8EPSS 1.8%Bazaar allows remote attackers to execute arbitrary commands via a bzr+ssh URL with initial dash character in hostname
發布日:2017/11/27修改日:2026/4/28
也稱為:DEBIAN-CVE-2017-14176
描述
Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.
受影響套件(5)
- Debian/breezyfrom 0, < 3.0.0~bzr6772-1
- Debian/bzrfrom 0, < 2.7.0+bzr6622-7
- Debian/bzrfrom 0, < 2.6.0+bzr6595-6+deb8u1
- PyPI/bzrfrom 0, <= 2.7.0
- PyPI/bzr
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-14176
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2017-14176
- PATCHhttps://bugzilla.redhat.com/show_bug.cgi?id=1486685
- REPORThttp://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14176.html
- REPORThttps://bugs.debian.org/874429
- REPORThttps://bugs.launchpad.net/bzr/+bug/1710979
- REPORThttps://bugzilla.suse.com/show_bug.cgi?id=1058214
- REPORThttps://www.debian.org/security/2017/dsa-4052
- REPORThttp://www.ubuntu.com/usn/usn-3411-1
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/bzr/PYSEC-2017-149.yaml