← Back

Dulwich Project

dulwich_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Dulwich
dulwich

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dulwich Project
1Dulwich
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836...Show more
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.Show less
2Debian
Dulwich Project
2Debian Linux
Dulwich
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.
2Debian
Dulwich Project
2Debian Linux
Dulwich
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking...Show more
The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.Show less