Vulnerability CVE-2008-5916


Published: 2009-01-20   Modified: 2012-02-13

Description:
gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and executing a crafted gitweb query.

See advisories in our WLB2 database:
Topic
Author
Date
Low
gitweb local privilege escalation
Junio C Hamano
22.01.2009

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
GIT -> GIT 

 References:
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01170.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01169.html
http://xforce.iss.net/xforce/xfdb/47528
http://www.ubuntu.com/usn/USN-723-1
http://www.openwall.com/lists/oss-security/2009/01/20/2
http://www.openwall.com/lists/oss-security/2009/01/15/2
http://www.gentoo.org/security/en/glsa/glsa-200903-15.xml
http://securityreason.com/securityalert/4922
http://secunia.com/advisories/34194
http://secunia.com/advisories/33964
http://secunia.com/advisories/33282
http://osvdb.org/50918
http://marc.info/?l=linux-kernel&m=122975564100863&w=2
:
http://marc.info/?l=git&m=122975564100860&w=2

Copyright 2022, cxsecurity.com

 

Back to Top