
Proof-of-Concept-Exploit für CVE-2018-11235, der Remotecodeausführung über bösartige Git-Submodule mit Build-Skript und Analyse demonstriert.
chybeta@ubuntu ~> git clone https://github.com/CHYbeta/CVE-2018-11235-DEMO.git
chybeta@ubuntu ~> cd CVE-2018-11235-DEMO
chybeta@ubuntu ~/CVE-2018-11235-DEMO> /usr/local/bin/git --version
git version 2.17.0
chybeta@ubuntu ~/CVE-2018-11235-DEMO> ./build.sh
