Vulnerability RUSTSEC-2023-0064
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 years ago
September 23, 2023 at 12:00 PM UTC
gix-transport code execution vulnerability
0.25.4 - 0.36.0
0.25.4 - 0.36.0
Summary
gix-transport code execution vulnerability
Details
The gix-transport crate prior to the patched version 0.36.1 would allow attackers to use malicious ssh clone URLs to pass arbitrary arguments to the ssh program, leading to arbitrary code execution.
PoC: gix clone 'ssh://-oProxyCommand=open$IFS-aCalculator/foo'
This will launch a calculator on OSX.
See https://secure.phabricator.com/T12961 for more details on similar vulnerabilities in git.
Thanks to vin01 for disclosing the issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 months ago
gix-transport: HTTP credentials leaked to redirected host in curl backend
0.25.4 - 0.55.1 GHSA-9857-6mw7-fq2m
0.25.4 - 0.55.1 GHSA-9857-6mw7-fq2m
Medium Risk
2 years ago
gix-transport indirect code execution via malicious username
0.25.4 - 0.41.3 GHSA-98p4-xjmm-8mfh
0.25.4 - 0.41.3 GHSA-98p4-xjmm-8mfh
Unknown
2 years ago
gix-transport indirect code execution via malicious username
0.25.4 - 0.41.3 RUSTSEC-2024-0335
0.25.4 - 0.41.3 RUSTSEC-2024-0335
Medium Risk
3 years ago
gix-transport code execution vulnerability
0.25.4 - 0.36.0 GHSA-rrjw-j4m2-mf34
0.25.4 - 0.36.0 GHSA-rrjw-j4m2-mf34
Impacted packages
Timeline
Published
3 years ago
September 23, 2023 at 12:00 PM UTC
Fixed (0.36.1)
3 years ago
September 25, 2023 at 06:29 AM UTC
Last Modified
11 months ago
October 28, 2025 at 06:02 AM UTC