VDB
CVE-2023-25815
CVE-2023-25815
PUBLISHED
In git existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund einer unzureichenden Eingabevalidierung im "git submodule deinit" und in der Art und Weise, wie Git lokalisierte Nachrichten verarbeitet. Ein entfernter, anonymer oder lokaler Angreifer kann diese Schwachstellen ausnutzen, um die Git-Konfiguration zu manipulieren oder dem Benutzer eine bösartige Nachricht anzuzeigen. Das erfolgreiche Ausnutzen einer dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.10% · 27.1th percentile
Risk Scores
EPSS Score
0.10%
27.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Visual Studio 2019 version 16.11 | |
| Open Source | Open Source git <2.40.1 | |
| Dell | Dell NetWorker <vproxy 19.8.0.3 | |
| Hitachi | Hitachi Storage Virtual Storage Platform | |
| Amazon | Amazon Linux 2 | |
| Fedora | Fedora Linux | |
| Microsoft | Microsoft Visual Studio Code | |
| Microsoft | Microsoft .NET Framework 3.5 | |
| Dell | Dell ECS <3.8.1.0 | |
| Open Source | Open Source git <2.32.7 | |
| Microsoft | Microsoft Azure DevOps Server 2020.1.2 | |
| Microsoft | Microsoft .NET Framework 3.5.1 | |
| Microsoft | Microsoft .NET Framework 4.7.1 | |
| Xerox | Xerox FreeFlow Print Server v9 | |
| Open Source | Open Source git <2.37.7 | |
| Open Source | Open Source git <2.35.8 | |
| Open Source | Open Source git <2.34.8 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.0 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.6 | |
| Dell | Dell NetWorker <vproxy 19.9.0.2 |
…and 35 more
Exploit Intelligence
- .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (circl)
- https://axcheron.github.io/exploit-101-format-strings/#writing-to-the-stack (cve.org)
- rules.yar (github-yara)
- CVE-2023-4863.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
…and 6 more exploits
Timeline
- Jan 2, 2022 Fix PR Merged
- Apr 25, 2023 CVE Published
- Apr 26, 2023 EPSS Score
- Jun 2, 2023 EPSS Score
- Jul 9, 2023 EPSS Score
- Aug 16, 2023 EPSS Score
- Sep 22, 2023 EPSS Score
- Oct 5, 2023 PoC Published
- Oct 29, 2023 EPSS Score
- Dec 5, 2023 EPSS Score
- Jan 12, 2024 EPSS Score
- Feb 18, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0794.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0794 advisory
- https://www.dell.com/support/kbdoc/000223839/dsa-2024-= advisory
- https://www.dell.com/support/kbdoc/en-us/000209268/dsa-2023-014-dell-poweredge-server-security-update-for-intel-february-2023-security-advisories-2023-1-ipu advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1072.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1072 advisory
- https://seclists.org/oss-sec/2023/q2/104 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014591.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014673.html advisory
- https://ubuntu.com/security/notices/USN-6050-1 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-May/014719.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-May/014775.html advisory
- https://ubuntu.com/security/notices/USN-6050-2 advisory
- https://access.redhat.com/errata/RHSA-2023:3192 advisory
- https://access.redhat.com/errata/RHSA-2023:3248 advisory
- https://access.redhat.com/errata/RHSA-2023:3247 advisory
- https://access.redhat.com/errata/RHSA-2023:3246 advisory
- https://access.redhat.com/errata/RHSA-2023:3245 advisory
- https://access.redhat.com/errata/RHSA-2023:3243 advisory
- http://linux.oracle.com/errata/ELSA-2023-3245.html advisory
…and 42 more