CVE-2015-7545
Publication date 9 December 2015
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| git | ||
| 14.04 LTS trusty |
Fixed 1:1.9.1-1ubuntu0.2
|
|
Patch details
| Package | Patch details |
|---|---|
| git |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
9.8 · Critical
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Related Ubuntu Security Notices (USN)
- USN-2835-1
- Git vulnerability
- 15 December 2015