The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade git-emailUpgrade gitkUpgrade emacs-gitUpgrade emacs-git-elUpgrade git-allUpgrade git-svnUpgrade git-cvsUpgrade git-daemonUpgrade perl-GitUpgrade gitUpgrade git-guiUpgrade gitweb | Dec 1, 2016 | Mar 8, 2013 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 1.7.9.2-0.175.2.11.0.2.0 on Solaris 11.2 | May 29, 2017 | Mar 8, 2013 |
| Oracle_linux | — | Upgrade git-svnUpgrade git-cvsUpgrade gitkUpgrade git-daemonUpgrade gitUpgrade perl-GitUpgrade emacs-git-elUpgrade git-guiUpgrade gitwebUpgrade git-allUpgrade git-emailUpgrade emacs-git | Mar 28, 2016 | Mar 8, 2013 |
| Suse | — | Upgrade gitkUpgrade git-emailUpgrade git-daemonUpgrade git-svnUpgrade git-daemon-debuginfoUpgrade git-cvsUpgrade gitUpgrade git-coreUpgrade git-debugsourceUpgrade sle-sdk-releaseUpgrade git-core-debuginfoUpgrade git-archUpgrade git-remote-helpersUpgrade git-webUpgrade git-gui | Dec 12, 2013 | Mar 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub