CVE-2017-16228

CRITICAL

dulwich < 0.18.5 - Remote Code Execution via SSH URL Hostname

Title source: llm
STIX 2.1

Description

Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://tracker.debian.org/news/882440
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/
Product, Vendor Advisory x_refsource_misc
https://www.dulwich.io/code/dulwich/

Scores

CVSS v3 9.8
EPSS 0.0339
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
dulwich_project/dulwich < 0.18.4
pypi/dulwich 0 - 0.18.5PyPI
Published Oct 29, 2017
Tracked Since Feb 18, 2026