CVE-2017-1000117

A malicious third-party can give a crafted "ssh://…" URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim’s machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone –recurse-submodules" to trigger the vulnerability.

Date published : 2017-10-03

http://www.securityfocus.com/bid/100283

https://support.apple.com/HT208103