VDB
KO

PYSEC-2015-34

Details

The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / dulwich
Introduced in: 0 Fixed in: 0.9.9
Fix pip install --upgrade 'dulwich>=0.9.9'

References