Vulnerabilities > CVE-2017-16228 - Unspecified vulnerability in Dulwich Project Dulwich

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
dulwich-project
nessus

Summary

Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.

Vulnerable Configurations

Part Description Count
Application
Dulwich_Project
57

Nessus

  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2018-801.NASL
    descriptionThis update for python-dulwich to version 0.18.5 fixes this security issue : - CVE-2017-16228: Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (bsc#1066430). For detailed changes please see https://www.dulwich.io/code/dulwich/ This update was imported from the SUSE:SLE-12:Update update project.
    last seen2020-06-05
    modified2018-08-07
    plugin id111563
    published2018-08-07
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/111563
    titleopenSUSE Security Update : python-dulwich (openSUSE-2018-801)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-5DD9B12179.NASL
    descriptionUpdate to 0.18.6 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2018-01-15
    plugin id105887
    published2018-01-15
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/105887
    titleFedora 27 : python-dulwich (2017-5dd9b12179)