Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-19486

Description

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

POC

Reference

No PoCs from references.

Github

- https://github.com/KorayAgaya/TrivyWeb

- https://github.com/Mohzeela/external-secret

- https://github.com/lacework/up-and-running-packer

- https://github.com/scottford-lw/up-and-running-packer

- https://github.com/siddharthraopotukuchi/trivy

- https://github.com/simiyo/trivy

- https://github.com/t31m0/Vulnerability-Scanner-for-Containers

- https://github.com/umahari/security