CVE-2018-1000021

Description

GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).

Risk Information

Base Score
5.0
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.372

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Git (X64) 2.15.1Windows
Multiple vulnerabilities affected in Git 2.15.1Windows
Vulnerabilities CVE-2018-1000021,CVE-2018-11233,CVE-2018-11235 are affected in Git (X64) 2.15.1Windows
Vulnerabilities CVE-2018-1000021,CVE-2018-11233,CVE-2018-11235 are affected in Git 2.15.1Windows
Improper Input Validation Vulnerability (CVE-2018-1000021)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-319947Git (x64) (2.32.0)
PATCH-342449Git (2.47.0.2)
PATCH-352878Git (x64) (2.51.2)
PATCH-350752Git (2.50.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234