Search CVE reports
1811 – 1820 of 57461 results
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes...
1 affected package
sshfs-fuse
| Package | 16.04 LTS |
|---|---|
| sshfs-fuse | Needs evaluation |
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read...
1 affected package
python-git
| Package | 16.04 LTS |
|---|---|
| python-git | Needs evaluation |
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally...
1 affected package
libnet-oauth-perl
| Package | 16.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is...
1 affected package
libnet-oauth-perl
| Package | 16.04 LTS |
|---|---|
| libnet-oauth-perl | Needs evaluation |
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null...
1 affected package
busybox
| Package | 16.04 LTS |
|---|---|
| busybox | Needs evaluation |