PublicDateAtUSN: 2017-08-10 18:00:00 UTC Candidate: CVE-2017-9800 CRD: 2017-08-10 18:00:00 UTC PublicDate: 2017-08-11 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9800 https://subversion.apache.org/security/CVE-2017-9800-advisory.txt https://ubuntu.com/security/notices/USN-3388-1 https://ubuntu.com/security/notices/USN-3388-2 Description: A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://. Ubuntu-Description: Joern Schneeweisz discovered that Subversion did not properly handle host names in 'svn+ssh://' URLs. A remote attacker could use this to construct a subversion repository that when accessed could run arbitrary code with the privileges of the user. Notes: Bugs: Priority: medium Discovered-by: Joern Schneeweisz Assigned-to: sbeattie CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_subversion: upstream_subversion: needs-triage precise/esm_subversion: released (1.6.17dfsg-3ubuntu3.7) trusty_subversion: released (1.8.8-1ubuntu3.3) trusty/esm_subversion: DNE (trusty was released [1.8.8-1ubuntu3.3]) vivid/ubuntu-core_subversion: DNE xenial_subversion: released (1.9.3-2ubuntu1.1) esm-infra/xenial_subversion: released (1.9.3-2ubuntu1.1) zesty_subversion: released (1.9.5-1ubuntu1.1) artful_subversion: not-affected (1.9.5-1ubuntu3) devel_subversion: not-affected (1.9.5-1ubuntu3)