CVE-2017-1000117
65Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon0 days
Published on NVDOct 4
1st PoCAug 11
metasploitAug 10
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
24 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Fixed
17 products (342 components)
Red Hat Mobile Application Platform 4.5 · Red Hat Enterprise Linux Server Optional (v. 7) · Red Hat Enterprise Linux Client Optional (v. 7) · Red Hat Enterprise Linux ComputeNode Optional (v. 7) · Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) · and others 12
Not affected
6 products — because the vulnerable code is not present in the product
Red Hat BPM Suite 6 · Red Hat JBoss A-MQ 6 · Red Hat JBoss BRMS 6 · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Fuse 6 · and others 1
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
Affected products
n/a · n/apublic PoCs found — 24✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/42599githubgithub.com/greymd/CVE-2017-1000117★ 136githubgithub.com/Manouchehri/CVE-2017-1000117★ 15githubgithub.com/timwr/CVE-2017-1000117★ 7githubgithub.com/ieee0824/CVE-2017-1000117★ 4githubgithub.com/AnonymKing/CVE-2017-1000117★ 3githubgithub.com/VulApps/CVE-2017-1000117★ 3githubgithub.com/nkoneko/CVE-2017-1000117★ 2githubgithub.com/sasairc/CVE-2017-1000117_wasawasa★ 1githubgithub.com/leezp/CVE-2017-1000117★ 1githubgithub.com/alilangtest/CVE-2017-1000117★ 0githubgithub.com/cved-sources/cve-2017-1000117★ 0githubgithub.com/Jerry-zhuang/CVE-2017-1000117★ 0githubgithub.com/thelastbyte/CVE-2017-1000117★ 0githubgithub.com/Shadow5523/CVE-2017-1000117-test★ 0githubgithub.com/ikmski/CVE-2017-1000117★ 0githubgithub.com/rootclay/CVE-2017-1000117★ 0githubgithub.com/takehaya/CVE-2017-1000117★ 0githubgithub.com/chenzhuo0618/test★ 0githubgithub.com/siling2017/CVE-2017-1000117★ 0githubgithub.com/ieee0824/CVE-2017-1000117-sl★ 0githubgithub.com/chu1337/CVE-2017-1000117★ 0githubgithub.com/shogo82148/Fix-CVE-2017-1000117★ 0cve_referencewww.exploit-db.com/exploits/42599/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2017:2484https://access.redhat.com/errata/RHSA-2017:2485https://access.redhat.com/errata/RHSA-2017:2491https://access.redhat.com/errata/RHSA-2017:2674https://access.redhat.com/errata/RHSA-2017:2675https://security.gentoo.org/glsa/201709-10https://support.apple.com/HT208103https://www.exploit-db.com/exploits/42599/https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1466490.htmlhttp://www.debian.org/security/2017/dsa-3934http://www.securityfocus.com/bid/100283http://www.securitytracker.com/id/1039131