CVE-2019-1348
published 2020-01-24CVE-2019-1348: An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks…
PriorityP414low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.43%
34.7th percentile
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | — | — |
| debian | git | < git 1:2.24.0-2 (bookworm) | git 1:2.24.0-2 (bookworm) |
| git-scm | git | >= 2.14.0 < 2.14.6 | 2.14.6 |
| git-scm | git | >= 2.15.0 < 2.15.4 | 2.15.4 |
| git-scm | git | >= 2.16.0 < 2.16.6 | 2.16.6 |
| git-scm | git | >= 2.17.0 < 2.17.3 | 2.17.3 |
| git-scm | git | >= 2.18.0 < 2.18.2 | 2.18.2 |
| git-scm | git | >= 2.19.0 < 2.19.3 | 2.19.3 |
| git-scm | git | >= 2.20.0 < 2.20.2 | 2.20.2 |
| git-scm | git | >= 2.21.0 < 2.21.1 | 2.21.1 |
| git-scm | git | >= 2.22.0 < 2.22.2 | 2.22.2 |
| git-scm | git | >= 2.23.0 < 2.23.1 | 2.23.1 |
| git-scm | git | >= 2.24.0 < 2.24.1 | 2.24.1 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| microsoft_corporation | git | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2019-1348: An issue was found in Git before v2
osv·2020-01-24·CVSS 3.3
CVE-2019-1348 [LOW] CVE-2019-1348: An issue was found in Git before v2
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
Red Hat
git: Arbitrary path overwriting via export-marks in-stream command feature
vendor_redhat·2019-12-10·CVSS 3.3
CVE-2019-1348 [LOW] CWE-20 git: Arbitrary path overwriting via export-marks in-stream command feature
git: Arbitrary path overwriting via export-marks in-stream command feature
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
A flaw was found in the git fast-import command where it provides the export-marks feature that may unexpectedly overwrite arbitrary paths. An attacker can abuse this flaw if they can control the input passed to the fast-import command by using the export-marks feature and overwrite arbitrary files, but would not have complete control on the content of the file.
Mitigation: Avoid running `git fast-import` on untrusted input.
P
Ubuntu
Git vulnerabilities
vendor_ubuntu·2019-12-10
CVE-2019-1348 Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Joern Schneeweisz and Nicolas Joly discovered that Git contained various
security flaws. An attacker could possibly use these issues to overwrite
arbitrary paths, execute arbitrary code, and overwrite files in the .git
directory.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2019-1348: Xcode 11.2
vendor_apple·2019-10-31·CVSS 3.3
CVE-2019-1348 [LOW] CVE-2019-1348: Xcode 11.2
Apple Security Update: About the security content of Xcode 11.2
Product: Xcode
Version: 11.2
CVE: CVE-2019-1348
Component: Git
Impact: Git could allow a remote malicious user to bypass security restrictions, caused by a flaw in the --export-marks option of git fast-import
Description: An input validation issue was addressed.
Debian
CVE-2019-1348: git - An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2...
vendor_debian·2019·CVSS 3.3
CVE-2019-1348 [LOW] CVE-2019-1348: git - An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2...
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1348 git: Arbitrary path overwriting via export-marks command option [fedora-all]
bugzilla·2019-12-11·CVSS 3.3
CVE-2019-1348 [LOW] CVE-2019-1348 git: Arbitrary path overwriting via export-marks command option [fedora-all]
CVE-2019-1348 git: Arbitrary path overwriting via export-marks command option [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2019-1348 git: Arbitrary path overwriting via export-marks in-stream command feature
bugzilla·2019-12-10·CVSS 3.3
CVE-2019-1348 [LOW] CVE-2019-1348 git: Arbitrary path overwriting via export-marks in-stream command feature
CVE-2019-1348 git: Arbitrary path overwriting via export-marks in-stream command feature
The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
Discussion:
Created git tracking bugs for this issue:
Affects: fedora-all [bug 1781955]
---
oss-security mailing list reference:
https://www.openwall.com/lists/oss-security/2019/12/13/1
---
External References:
https://github.com/git/git/security/advisories/GHSA-2pw3-gwg9-8pqr
---
Upstream fix:
https://github.com/git/git/commit/68061e3470210703cb15594194718d35094afdc0
---
Mitigation:
Avoid running `git fast-import` on untr
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2020:0228https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#uhttps://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30https://security.gentoo.org/glsa/202003-42https://support.apple.com/kb/HT210729http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2020:0228https://lore.kernel.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/T/#uhttps://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30https://security.gentoo.org/glsa/202003-42https://support.apple.com/kb/HT210729
2020-01-24
Published