CVE-2014-9390
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
EPSS 77.15% · 99.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:14.04:LTS | libgit2 | 0, 0.19.0-2, 0.19.0-2ubuntu0.4 |
| Ubuntu:14.04:LTS | mercurial | 2.7.2-1, 2.6.3-1, 2.8.1-2 |
| Ubuntu:14.04:LTS | git | 1:1.8.5-1, 1:1.8.5.1-1, 1:1.8.5.2-2 |
Exploit Intelligence
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
- pyonpyon (github-poc)
…and 17 more exploits
Timeline
- Dec 18, 2014 CVE Published
- Mar 23, 2017 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Dec 21, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2014-9390 third-party-advisory
- http://git-blame.blogspot.com.es/2014/12/git-1856-195-205-214-and-221-and.html third-party-advisory
- http://mercurial.selenic.com/wiki/WhatsNew#Mercurial_3.2.3_.282014-12-18.29 third-party-advisory
- http://article.gmane.org/gmane.linux.kernel/1853266 third-party-advisory
- https://developer.atlassian.com/blog/2014/12/securing-your-git-server/ third-party-advisory
- https://ubuntu.com/security/notices/USN-2470-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2014-9390 third-party-advisory