Sourcetree Git Arbitrary Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 2 Nov 2018.

  1. Packet Storm

    Packet Storm Guest

    An attacker can exploit the embedded version of Git used in Sourcetree if they can commit to a Git repository linked in Sourcetree. This allows them to execute arbitrary code on systems running a vulnerable version of Sourcetree for macOS. Versions of Sourcetree for macOS starting with version 1.02b before version 3.0.0 are affected by this vulnerability. Versions of Sourcetree for Windows starting with version 0.5.1.0 before version 3.0.0 are affected by this vulnerability.

    Continue reading...
     

Share This Page

Loading...