CVE-2014-9706

Severity CVSS v4.0:
Pending analysis
Type:
CWE-19 Data Handling
Publication date:
31/03/2015
Last modified:
12/04/2025

Description

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:dulwich_project:dulwich:*:*:*:*:*:*:*:* 0.9.8 (including)