The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
References
Link Providers
https://www.spirityenterprise.com/pentest spirity
https://www.spirityenterprise.com/managed-detection-response spirity
http://lists.opensuse.org/opensuse-updates/2015-11/msg00066.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-2515.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3435 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2015/12/08/5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2015/12/09/8 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2015/12/11/7 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html cve-icon cve-icon
http://www.securityfocus.com/bid/78711 cve-icon cve-icon
http://www.securitytracker.com/id/1034501 cve-icon cve-icon
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.533255 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2835-1 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1269794 cve-icon cve-icon
https://github.com/git/git/blob/master/Documentation/RelNotes/2.3.10.txt cve-icon cve-icon
https://github.com/git/git/blob/master/Documentation/RelNotes/2.4.10.txt cve-icon cve-icon
https://github.com/git/git/blob/master/Documentation/RelNotes/2.5.4.txt cve-icon cve-icon
https://github.com/git/git/blob/master/Documentation/RelNotes/2.6.1.txt cve-icon cve-icon
https://kernel.googlesource.com/pub/scm/git/git/+/33cfccbbf35a56e190b79bdec5c85457c952a021 cve-icon cve-icon
https://lkml.org/lkml/2015/10/5/683 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2015-7545 cve-icon
https://security.gentoo.org/glsa/201605-01 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2015-7545 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T07:51:28.413Z

Reserved: 2015-09-29T00:00:00

Link: CVE-2015-7545

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-13T15:59:01.320

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-7545

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-10-05T00:00:00Z

Links: CVE-2015-7545 - Bugzilla