Risk Scores
EPSS Score
77.15%
99.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:14.04:LTS | libgit2 | 0, 0.19.0-2, 0.19.0-2ubuntu0.4 |
| Ubuntu:14.04:LTS | mercurial | 0, 2.8.2-1ubuntu1, 2.6.3-1 |
| Ubuntu:14.04:LTS | git | 1:1.8.5.3-1, 1:1.9~rc1-1, 0 |
Timeline
- Dec 18, 2014 CVE Published
- Mar 23, 2017 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 19, 2022 EPSS Score
- Jul 10, 2022 EPSS Score
- Oct 23, 2022 EPSS Score
- Feb 4, 2023 EPSS Score
- Mar 28, 2023 EPSS Score
- May 19, 2023 EPSS Score
- Aug 31, 2023 EPSS Score
- Nov 8, 2023 CVE Updated
References
- https://ubuntu.com/security/CVE-2014-9390 third-party-advisory
- http://git-blame.blogspot.com.es/2014/12/git-1856-195-205-214-and-221-and.html third-party-advisory
- http://mercurial.selenic.com/wiki/WhatsNew#Mercurial_3.2.3_.282014-12-18.29 third-party-advisory
- http://article.gmane.org/gmane.linux.kernel/1853266 third-party-advisory
- https://developer.atlassian.com/blog/2014/12/securing-your-git-server/ third-party-advisory
- https://ubuntu.com/security/notices/USN-2470-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2014-9390 third-party-advisory