Vulnerability Details CVE-2017-12976
git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2017-12976
-
cpe:2.3:a:git-annex_project:git-annex:-
-
cpe:2.3:a:git-annex_project:git-annex:0.02
-
cpe:2.3:a:git-annex_project:git-annex:0.03
-
cpe:2.3:a:git-annex_project:git-annex:0.04
-
cpe:2.3:a:git-annex_project:git-annex:0.05
-
cpe:2.3:a:git-annex_project:git-annex:0.06
-
cpe:2.3:a:git-annex_project:git-annex:0.07
-
cpe:2.3:a:git-annex_project:git-annex:0.08
-
cpe:2.3:a:git-annex_project:git-annex:0.09
-
cpe:2.3:a:git-annex_project:git-annex:0.10
-
cpe:2.3:a:git-annex_project:git-annex:0.11
-
cpe:2.3:a:git-annex_project:git-annex:0.12
-
cpe:2.3:a:git-annex_project:git-annex:0.13
-
cpe:2.3:a:git-annex_project:git-annex:0.14
-
cpe:2.3:a:git-annex_project:git-annex:0.15
-
cpe:2.3:a:git-annex_project:git-annex:0.17
-
cpe:2.3:a:git-annex_project:git-annex:0.18
-
cpe:2.3:a:git-annex_project:git-annex:0.19
-
cpe:2.3:a:git-annex_project:git-annex:0.20
-
cpe:2.3:a:git-annex_project:git-annex:0.20110316
-
cpe:2.3:a:git-annex_project:git-annex:0.20110320
-
cpe:2.3:a:git-annex_project:git-annex:0.20110325
-
cpe:2.3:a:git-annex_project:git-annex:0.20110328
-
cpe:2.3:a:git-annex_project:git-annex:0.20110401
-
cpe:2.3:a:git-annex_project:git-annex:0.20110417
-
cpe:2.3:a:git-annex_project:git-annex:0.20110419
-
cpe:2.3:a:git-annex_project:git-annex:0.20110420
-
cpe:2.3:a:git-annex_project:git-annex:0.20110425
-
cpe:2.3:a:git-annex_project:git-annex:0.20110503
-
cpe:2.3:a:git-annex_project:git-annex:0.20110516
-
cpe:2.3:a:git-annex_project:git-annex:0.20110521
-
cpe:2.3:a:git-annex_project:git-annex:0.20110522
-
cpe:2.3:a:git-annex_project:git-annex:0.20110601
-
cpe:2.3:a:git-annex_project:git-annex:0.20110610
-
cpe:2.3:a:git-annex_project:git-annex:0.21
-
cpe:2.3:a:git-annex_project:git-annex:0.22
-
cpe:2.3:a:git-annex_project:git-annex:0.23
-
cpe:2.3:a:git-annex_project:git-annex:0.24
-
cpe:2.3:a:git-annex_project:git-annex:0.25
-
cpe:2.3:a:git-annex_project:git-annex:3.20110624
-
cpe:2.3:a:git-annex_project:git-annex:3.20110702
-
cpe:2.3:a:git-annex_project:git-annex:3.20110705
-
cpe:2.3:a:git-annex_project:git-annex:3.20110707
-
cpe:2.3:a:git-annex_project:git-annex:3.20110719
-
cpe:2.3:a:git-annex_project:git-annex:3.20110817
-
cpe:2.3:a:git-annex_project:git-annex:3.20110819
-
cpe:2.3:a:git-annex_project:git-annex:3.20110902
-
cpe:2.3:a:git-annex_project:git-annex:3.20110906
-
cpe:2.3:a:git-annex_project:git-annex:3.20110915
-
cpe:2.3:a:git-annex_project:git-annex:3.20110928
-
cpe:2.3:a:git-annex_project:git-annex:3.20111011
-
cpe:2.3:a:git-annex_project:git-annex:3.20111025
-
cpe:2.3:a:git-annex_project:git-annex:3.20111105
-
cpe:2.3:a:git-annex_project:git-annex:3.20111107
-
cpe:2.3:a:git-annex_project:git-annex:3.20111111
-
cpe:2.3:a:git-annex_project:git-annex:3.20111122
-
cpe:2.3:a:git-annex_project:git-annex:3.20111203
-
cpe:2.3:a:git-annex_project:git-annex:3.20111211
-
cpe:2.3:a:git-annex_project:git-annex:3.20111231
-
cpe:2.3:a:git-annex_project:git-annex:3.20120105
-
cpe:2.3:a:git-annex_project:git-annex:3.20120106
-
cpe:2.3:a:git-annex_project:git-annex:3.20120113
-
cpe:2.3:a:git-annex_project:git-annex:3.20120115
-
cpe:2.3:a:git-annex_project:git-annex:3.20120116
-
cpe:2.3:a:git-annex_project:git-annex:3.20120123
-
cpe:2.3:a:git-annex_project:git-annex:3.20120227
-
cpe:2.3:a:git-annex_project:git-annex:3.20120229
-
cpe:2.3:a:git-annex_project:git-annex:3.20120230
-
cpe:2.3:a:git-annex_project:git-annex:3.20120309
-
cpe:2.3:a:git-annex_project:git-annex:3.20120315
-
cpe:2.3:a:git-annex_project:git-annex:3.20120405
-
cpe:2.3:a:git-annex_project:git-annex:3.20120406
-
cpe:2.3:a:git-annex_project:git-annex:3.20120418
-
cpe:2.3:a:git-annex_project:git-annex:3.20120430
-
cpe:2.3:a:git-annex_project:git-annex:3.20120511
-
cpe:2.3:a:git-annex_project:git-annex:3.20120522
-
cpe:2.3:a:git-annex_project:git-annex:3.20120605
-
cpe:2.3:a:git-annex_project:git-annex:3.20120611
-
cpe:2.3:a:git-annex_project:git-annex:3.20120614
-
cpe:2.3:a:git-annex_project:git-annex:3.20120624
-
cpe:2.3:a:git-annex_project:git-annex:3.20120629
-
cpe:2.3:a:git-annex_project:git-annex:3.20120721
-
cpe:2.3:a:git-annex_project:git-annex:3.20120807
-
cpe:2.3:a:git-annex_project:git-annex:3.20120825
-
cpe:2.3:a:git-annex_project:git-annex:3.20120924
-
cpe:2.3:a:git-annex_project:git-annex:3.20121001
-
cpe:2.3:a:git-annex_project:git-annex:3.20121009
-
cpe:2.3:a:git-annex_project:git-annex:3.20121010
-
cpe:2.3:a:git-annex_project:git-annex:3.20121016
-
cpe:2.3:a:git-annex_project:git-annex:3.20121017
-
cpe:2.3:a:git-annex_project:git-annex:3.20121112
-
cpe:2.3:a:git-annex_project:git-annex:3.20121126
-
cpe:2.3:a:git-annex_project:git-annex:3.20121127
-
cpe:2.3:a:git-annex_project:git-annex:3.20121211
-
cpe:2.3:a:git-annex_project:git-annex:3.20130102
-
cpe:2.3:a:git-annex_project:git-annex:3.20130107
-
cpe:2.3:a:git-annex_project:git-annex:3.20130114
-
cpe:2.3:a:git-annex_project:git-annex:3.20130124
-
cpe:2.3:a:git-annex_project:git-annex:3.20130207
-
cpe:2.3:a:git-annex_project:git-annex:3.20130216
-
cpe:2.3:a:git-annex_project:git-annex:4.20130227
-
cpe:2.3:a:git-annex_project:git-annex:4.20130314
-
cpe:2.3:a:git-annex_project:git-annex:4.20130323
-
cpe:2.3:a:git-annex_project:git-annex:4.20130405
-
cpe:2.3:a:git-annex_project:git-annex:4.20130417
-
cpe:2.3:a:git-annex_project:git-annex:4.20130501
-
cpe:2.3:a:git-annex_project:git-annex:4.20130516
-
cpe:2.3:a:git-annex_project:git-annex:4.20130521
-
cpe:2.3:a:git-annex_project:git-annex:4.20130521.1
-
cpe:2.3:a:git-annex_project:git-annex:4.20130521.2
-
cpe:2.3:a:git-annex_project:git-annex:4.20130601
-
cpe:2.3:a:git-annex_project:git-annex:4.20130621
-
cpe:2.3:a:git-annex_project:git-annex:4.20130627
-
cpe:2.3:a:git-annex_project:git-annex:4.20130709
-
cpe:2.3:a:git-annex_project:git-annex:4.20130723
-
cpe:2.3:a:git-annex_project:git-annex:4.20130802
-
cpe:2.3:a:git-annex_project:git-annex:4.20130815
-
cpe:2.3:a:git-annex_project:git-annex:4.20130909
-
cpe:2.3:a:git-annex_project:git-annex:4.20130911
-
cpe:2.3:a:git-annex_project:git-annex:4.20130920
-
cpe:2.3:a:git-annex_project:git-annex:4.20131002
-
cpe:2.3:a:git-annex_project:git-annex:4.20131024
-
cpe:2.3:a:git-annex_project:git-annex:4.20131101
-
cpe:2.3:a:git-annex_project:git-annex:4.20131106
-
cpe:2.3:a:git-annex_project:git-annex:5.20131118
-
cpe:2.3:a:git-annex_project:git-annex:5.20131120
-
cpe:2.3:a:git-annex_project:git-annex:5.20131127
-
cpe:2.3:a:git-annex_project:git-annex:5.20131130
-
cpe:2.3:a:git-annex_project:git-annex:5.20131213
-
cpe:2.3:a:git-annex_project:git-annex:5.20131221
-
cpe:2.3:a:git-annex_project:git-annex:5.20131230
-
cpe:2.3:a:git-annex_project:git-annex:5.20140107
-
cpe:2.3:a:git-annex_project:git-annex:5.20140116
-
cpe:2.3:a:git-annex_project:git-annex:5.20140127
-
cpe:2.3:a:git-annex_project:git-annex:5.20140210
-
cpe:2.3:a:git-annex_project:git-annex:5.20140221
-
cpe:2.3:a:git-annex_project:git-annex:5.20140227
-
cpe:2.3:a:git-annex_project:git-annex:5.20140306
-
cpe:2.3:a:git-annex_project:git-annex:5.20140320
-
cpe:2.3:a:git-annex_project:git-annex:5.20140402
-
cpe:2.3:a:git-annex_project:git-annex:5.20140411
-
cpe:2.3:a:git-annex_project:git-annex:5.20140412
-
cpe:2.3:a:git-annex_project:git-annex:5.20140421
-
cpe:2.3:a:git-annex_project:git-annex:5.20140517
-
cpe:2.3:a:git-annex_project:git-annex:5.20140529
-
cpe:2.3:a:git-annex_project:git-annex:5.20140606
-
cpe:2.3:a:git-annex_project:git-annex:5.20140613
-
cpe:2.3:a:git-annex_project:git-annex:5.20140707
-
cpe:2.3:a:git-annex_project:git-annex:5.20140709
-
cpe:2.3:a:git-annex_project:git-annex:5.20140717
-
cpe:2.3:a:git-annex_project:git-annex:5.20140817
-
cpe:2.3:a:git-annex_project:git-annex:5.20140831
-
cpe:2.3:a:git-annex_project:git-annex:5.20140915
-
cpe:2.3:a:git-annex_project:git-annex:5.20140919
-
cpe:2.3:a:git-annex_project:git-annex:5.20140926
-
cpe:2.3:a:git-annex_project:git-annex:5.20140927
-
cpe:2.3:a:git-annex_project:git-annex:5.20141013
-
cpe:2.3:a:git-annex_project:git-annex:5.20141024
-
cpe:2.3:a:git-annex_project:git-annex:5.20141125
-
cpe:2.3:a:git-annex_project:git-annex:5.20141203
-
cpe:2.3:a:git-annex_project:git-annex:5.20141219
-
cpe:2.3:a:git-annex_project:git-annex:5.20141231
-
cpe:2.3:a:git-annex_project:git-annex:5.20150113
-
cpe:2.3:a:git-annex_project:git-annex:5.20150205
-
cpe:2.3:a:git-annex_project:git-annex:5.20150219
-
cpe:2.3:a:git-annex_project:git-annex:5.20150317
-
cpe:2.3:a:git-annex_project:git-annex:5.20150327
-
cpe:2.3:a:git-annex_project:git-annex:5.20150406
-
cpe:2.3:a:git-annex_project:git-annex:5.20150409
-
cpe:2.3:a:git-annex_project:git-annex:5.20150420
-
cpe:2.3:a:git-annex_project:git-annex:5.20150508
-
cpe:2.3:a:git-annex_project:git-annex:5.20150522
-
cpe:2.3:a:git-annex_project:git-annex:5.20150528
-
cpe:2.3:a:git-annex_project:git-annex:5.20150617
-
cpe:2.3:a:git-annex_project:git-annex:5.20150710
-
cpe:2.3:a:git-annex_project:git-annex:5.20150727
-
cpe:2.3:a:git-annex_project:git-annex:5.20150731
-
cpe:2.3:a:git-annex_project:git-annex:5.20150812
-
cpe:2.3:a:git-annex_project:git-annex:5.20150824
-
cpe:2.3:a:git-annex_project:git-annex:5.20150916
-
cpe:2.3:a:git-annex_project:git-annex:5.20150930
-
cpe:2.3:a:git-annex_project:git-annex:5.20151019
-
cpe:2.3:a:git-annex_project:git-annex:5.20151102
-
cpe:2.3:a:git-annex_project:git-annex:5.20151102.1
-
cpe:2.3:a:git-annex_project:git-annex:5.20151116
-
cpe:2.3:a:git-annex_project:git-annex:5.20151208
-
cpe:2.3:a:git-annex_project:git-annex:5.20151218
-
cpe:2.3:a:git-annex_project:git-annex:6.20160114
-
cpe:2.3:a:git-annex_project:git-annex:6.20160126
-
cpe:2.3:a:git-annex_project:git-annex:6.20160211
-
cpe:2.3:a:git-annex_project:git-annex:6.20160217
-
cpe:2.3:a:git-annex_project:git-annex:6.20160229
-
cpe:2.3:a:git-annex_project:git-annex:6.20160318
-
cpe:2.3:a:git-annex_project:git-annex:6.20160412
-
cpe:2.3:a:git-annex_project:git-annex:6.20160418
-
cpe:2.3:a:git-annex_project:git-annex:6.20160419
-
cpe:2.3:a:git-annex_project:git-annex:6.20160511
-
cpe:2.3:a:git-annex_project:git-annex:6.20160527
-
cpe:2.3:a:git-annex_project:git-annex:6.20160613
-
cpe:2.3:a:git-annex_project:git-annex:6.20160619
-
cpe:2.3:a:git-annex_project:git-annex:6.20160719
-
cpe:2.3:a:git-annex_project:git-annex:6.20160808
-
cpe:2.3:a:git-annex_project:git-annex:6.20160907
-
cpe:2.3:a:git-annex_project:git-annex:6.20160923
-
cpe:2.3:a:git-annex_project:git-annex:6.20161012
-
cpe:2.3:a:git-annex_project:git-annex:6.20161027
-
cpe:2.3:a:git-annex_project:git-annex:6.20161031
-
cpe:2.3:a:git-annex_project:git-annex:6.20161111
-
cpe:2.3:a:git-annex_project:git-annex:6.20161118
-
cpe:2.3:a:git-annex_project:git-annex:6.20161210
-
cpe:2.3:a:git-annex_project:git-annex:6.20170101
-
cpe:2.3:a:git-annex_project:git-annex:6.20170101.1
-
cpe:2.3:a:git-annex_project:git-annex:6.20170214
-
cpe:2.3:a:git-annex_project:git-annex:6.20170228
-
cpe:2.3:a:git-annex_project:git-annex:6.20170301
-
cpe:2.3:a:git-annex_project:git-annex:6.20170301.1
-
cpe:2.3:a:git-annex_project:git-annex:6.20170321
-
cpe:2.3:a:git-annex_project:git-annex:6.20170510
-
cpe:2.3:a:git-annex_project:git-annex:6.20170519
-
cpe:2.3:a:git-annex_project:git-annex:6.20170520