7.5
CVSSv2

CVE-2014-9706

Published: 31/03/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The build_index_from_tree function in index.py in Dulwich prior to 0.9.9 allows remote malicious users to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

dulwich project dulwich

Vendor Advisories

Multiple vulnerabilities have been discovered in Dulwich, a Python implementation of the file formats and protocols used by the Git version control system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-9706 It was discovered that Dulwich allows writing to files under git/ when checking out wo ...
Debian Bug report logs - #780958 dulwich: CVE-2015-0838: buffer overflow in C implementation of pack apply_delta() Package: src:dulwich; Maintainer for src:dulwich is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 22 Mar 2015 1 ...
Debian Bug report logs - #780989 dulwich: CVE-2014-9706: does not prevent to write files in commits with invalid paths to working tree Package: src:dulwich; Maintainer for src:dulwich is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date ...