Input validation error - CVE-2017-16228
Published: October 29, 2017 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
Affected software
aalib (Alpine package)
python-dulwich
Fedora
Opensuse
How to mitigate CVE-2017-16228
python-dulwich - addressed in versions 0.18.6-1.fc25, 0.18.6-1.fc27