An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.
{ "binaries": [ { "binary_name": "git", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-all", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-arch", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-core", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-cvs", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-daemon-run", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-daemon-sysvinit", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-doc", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-el", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-email", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-gui", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-man", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-mediawiki", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "git-svn", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "gitk", "binary_version": "1:2.7.4-0ubuntu1.7" }, { "binary_name": "gitweb", "binary_version": "1:2.7.4-0ubuntu1.7" } ], "ubuntu_priority": "low", "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "git", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-all", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-cvs", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-daemon-run", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-daemon-sysvinit", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-dbgsym", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-doc", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-el", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-email", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-gui", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-man", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-mediawiki", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "git-svn", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "gitk", "binary_version": "1:2.17.1-1ubuntu0.5" }, { "binary_name": "gitweb", "binary_version": "1:2.17.1-1ubuntu0.5" } ], "ubuntu_priority": "low", "availability": "No subscription required" }