Input validation error - CVE-2017-16228

 

Input validation error - CVE-2017-16228

Published: October 29, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33780
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16228
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.


Affected software

py-dulwich (Alpine package)
aalib (Alpine package)
python-dulwich
Fedora
Opensuse

How to mitigate CVE-2017-16228

Install update from vendor's website.

py-dulwich (Alpine package) - update to 0.18.6-r0
python-dulwich - addressed in versions 0.18.6-1.fc25, 0.18.6-1.fc27

External References

Related Security Bulletins