CVE-2019-1351
published 2020-01-24CVE-2019-1351: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
8.72%
94.5th percentile
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | git | < git 1:2.24.0-2 (bookworm) | git 1:2.24.0-2 (bookworm) |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| microsoft | microsoft_visual_studio_2017 | — | — |
| microsoft | microsoft_visual_studio_2017_version_15.9 | — | — |
| microsoft | microsoft_visual_studio_2019 | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.4 | — | — |
| microsoft | visual_studio_2017 | >= 15.0 < 15.9.18 | 15.9.18 |
| microsoft | visual_studio_2019 | >= 16.0 < 16.4.1 | 16.4.1 |
| msrc | microsoft_visual_studio_2017_version_15.0 | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.0 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Git for Visual Studio Tampering Vulnerability
vendor_msrc·2019-12-10·CVSS 7.5
CVE-2019-1351 [HIGH] Git for Visual Studio Tampering Vulnerability
Git for Visual Studio Tampering Vulnerability
Description: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories.
To exploit the vulnerability, an attacker must clone a file using a specially crafted path on a vulnerable system.
The security update fixes the vulnerability by ensuring Git for Visual Studio properly handles folder paths.
FAQ: I want to install the latest supported service baseline for Visual Studio. Do I need to install the previous versions first?
No. For both Visual Studio 2019 and Vis
Ubuntu
Git vulnerabilities
vendor_ubuntu·2019-12-10
CVE-2019-1348 Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Joern Schneeweisz and Nicolas Joly discovered that Git contained various
security flaws. An attacker could possibly use these issues to overwrite
arbitrary paths, execute arbitrary code, and overwrite files in the .git
directory.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
vendor_redhat·2019-12-10·CVSS 7.5
CVE-2019-1351 [HIGH] CWE-20 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Statement: This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6, 7, and 8 as this is a Windows only issue and it does not affect the Linux versions of git.
Package: git (Red Hat Enterprise Linux 6) - Not affected
Package: git (Red Hat Enterprise Linux 7) - Not affected
Package: git (Red Hat Enterprise Linux 8) - Not affected
Package: rh-git218-git (Red Hat Software Collections) - Not affected
Debian
CVE-2019-1351: git - A tampering vulnerability exists when Git for Visual Studio improperly handles v...
vendor_debian·2019·CVSS 7.5
CVE-2019-1351 [HIGH] CVE-2019-1351: git - A tampering vulnerability exists when Git for Visual Studio improperly handles v...
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
GHSA
GHSA-74x9-89m7-944x: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2019-1351 [MEDIUM] GHSA-74x9-89m7-944x: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
OSV
CVE-2019-1351: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability
osv·2020-01-24·CVSS 7.5
CVE-2019-1351 [HIGH] CVE-2019-1351: A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning [fedora-all]
bugzilla·2019-12-11·CVSS 7.5
CVE-2019-1351 [HIGH] CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning [fedora-all]
CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
bugzilla·2019-12-11·CVSS 7.5
CVE-2019-1351 [HIGH] CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
CVE-2019-1351 git: Git mistakes some paths for relative paths allowing writing outside of the worktree while cloning
While the only permitted drive letters for physical drives on Windows are letters of the US-English alphabet, this restriction does not apply to virtual drives assigned via subst :. Git mistook such paths for relative paths, allowing writing outside of the worktree while cloning.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
Discussion:
Created git tracking bugs for this issue:
Affects: fedora-all [bug 1781961]
---
Does this bug apply to Fedora (or RHEL)? The commit (https://git.kernel.org/pub/scm/git/git.git/commit/?id=f82a97eb9197c1e3768e72648f37ce0ca3233734) explicitly mentions mingw.
---
oss-se
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1351https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1351https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30
2020-01-24
Published