CVE-2019-1352
published 2020-01-24CVE-2019-1352: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution…
PriorityP359high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
24.01%
97.6th percentile
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | git | < git 1:2.24.0-2 (bookworm) | git 1:2.24.0-2 (bookworm) |
| debian | libgit2 | < libgit2 0.28.4+dfsg.1-2 (bookworm) | libgit2 0.28.4+dfsg.1-2 (bookworm) |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| git | git | >= 0 < 1:2.24.0-2 | 1:2.24.0-2 |
| libgit2 | libgit2 | < 0.28.4 | 0.28.4 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| me-and | cygwin-git | < 2.31.1-2 | 2.31.1-2 |
| microsoft | microsoft_visual_studio_2017 | — | — |
| microsoft | microsoft_visual_studio_2017_version_15.9 | — | — |
| microsoft | microsoft_visual_studio_2019 | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.4 | — | — |
| microsoft | visual_studio_2017 | >= 15.0 < 15.9.18 | 15.9.18 |
| microsoft | visual_studio_2019 | >= 16.0 < 16.4.1 | 16.4.1 |
| msrc | microsoft_visual_studio_2017_version_15.0 | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.0 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-993f-36vw-6mhm: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1349 [HIGH] GHSA-993f-36vw-6mhm: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
GHSA
GHSA-v94j-fmjr-xrgv: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1350 [HIGH] GHSA-v94j-fmjr-xrgv: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
GHSA
GHSA-57mj-9r29-rj3q: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1354 [HIGH] GHSA-57mj-9r29-rj3q: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.
GHSA
GHSA-w32v-c4gg-xc8p: An issue was discovered in libgit2 before 0
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-12278 [HIGH] CWE-20 GHSA-w32v-c4gg-xc8p: An issue was discovered in libgit2 before 0
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
GHSA
GHSA-74fq-3g57-65f7: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1352 [HIGH] GHSA-74fq-3g57-65f7: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
OSV
CVE-2020-12278: An issue was discovered in libgit2 before 0
osv·2020-04-27·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278: An issue was discovered in libgit2 before 0
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
OSV
CVE-2019-1350: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
osv·2020-01-24·CVSS 8.8
CVE-2019-1350 [HIGH] CVE-2019-1350: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
OSV
CVE-2019-1354: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
osv·2020-01-24·CVSS 8.8
CVE-2019-1354 [HIGH] CVE-2019-1354: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.
OSV
CVE-2019-1352: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
osv·2020-01-24·CVSS 8.8
CVE-2019-1352 [HIGH] CVE-2019-1352: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
OSV
CVE-2019-1349: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
osv·2020-01-24·CVSS 8.8
CVE-2019-1349 [HIGH] CVE-2019-1349: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution V
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
Debian
CVE-2020-12278: libgit2 - An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c ...
vendor_debian·2020·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278: libgit2 - An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c ...
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Scope: local
bookworm: resolved (fixed in 0.28.4+dfsg.1-2)
bullseye: resolved (fixed in 0.28.4+dfsg.1-2)
forky: resolved (fixed in 0.28.4+dfsg.1-2)
sid: resolved (fixed in 0.28.4+dfsg.1-2)
trixie: resolved (fixed in 0.28.4+dfsg.1-2)
Microsoft
Git for Visual Studio Remote Code Execution Vulnerability
vendor_msrc·2019-12-10·CVSS 8.8
CVE-2019-1352 [HIGH] Git for Visual Studio Remote Code Execution Vulnerability
Git for Visual Studio Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit the vulnerability, an attacker would first need to convince the user to clone a malicious repo.
The security update addresses the vulnerability by correcting how Git for Visual Studio validates command-line input.
FAQ: I want to install the lat
Red Hat
git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
vendor_redhat·2019-12-10·CVSS 8.8
CVE-2019-1349 [HIGH] CWE-20 git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
An improper input validation flaw was discovered in git in the way it handles git submodules. A remote attacker could abuse this flaw to trick a victim user into recursively cloning a malicious repository, which, under certain circumstances, could fool git into using the same git directory twice and potentially cause remote code execution.
Mitigation: Avoid running `git clone --recurse-submodules` and `git submodule update` wit
Ubuntu
Git vulnerabilities
vendor_ubuntu·2019-12-10
CVE-2019-1348 Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Joern Schneeweisz and Nicolas Joly discovered that Git contained various
security flaws. An attacker could possibly use these issues to overwrite
arbitrary paths, execute arbitrary code, and overwrite files in the .git
directory.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
vendor_redhat·2019-12-10·CVSS 8.8
CVE-2019-1352 [HIGH] CWE-73 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
Statement: Even if the code in the versions of git as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collections 3 is affected by this flaw, Red Hat does not support the NTFS filesystem. For this reason, the flaw has a Low Impact.
Package: git (Red Hat Enterprise Linux 6) - Not affected
Package: git (Red Hat Enterprise Linux 7) - Not affected
Red Hat
git: Git does not refuse to write out tracked files with backlashes in filenames
vendor_redhat·2019-12-10·CVSS 8.8
CVE-2019-1354 [HIGH] CWE-20 git: Git does not refuse to write out tracked files with backlashes in filenames
git: Git does not refuse to write out tracked files with backlashes in filenames
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.
Statement: This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6, 7, and 8 as this is a Windows only issue and it does not affect the Linux versions of git.
Package: git (Red Hat Enterprise Linux 6) - Not affected
Package: git (Red Hat Enterprise Linux 7) - Not affected
Package: git (Red Hat Enterprise Linux 8) - Not affected
Package: rh-git218-git (Red Hat Software Collections) - Not affected
Red Hat
git: Incorrect quoting of command-line arguments allowed remote code execution during a recursive clone
vendor_redhat·2019-12-10·CVSS 8.8
CVE-2019-1350 [HIGH] CWE-20 git: Incorrect quoting of command-line arguments allowed remote code execution during a recursive clone
git: Incorrect quoting of command-line arguments allowed remote code execution during a recursive clone
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
Statement: This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6, 7, and 8 as this is a Windows only issue and it does not affect the Linux versions of git.
Package: git (Red Hat Enterprise Linux 6) - Not affected
Package: git (Red Hat Enterprise Linux 7) - Not affected
Package: git (Red Hat Enterprise Linux 8) - Not affected
Package: rh-git218-git (Red Hat Software Collections) - Not affected
Red Hat
libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
vendor_redhat·2019-09-18·CVSS 8.8
CVE-2020-12278 [HIGH] CWE-73 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Statement: Even if the code in the versions of libgit2 as shipped with Red Hat Enterprise Linux 7, and 8 are affected by this flaw, Red Hat does not support the NTFS filesystem. For this reason, the flaw has a Low Impact.
Package: libgit2 (Red Hat Enterprise Linux 7) - Fix deferred
Package: libgit2 (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2019-1350: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
vendor_debian·2019·CVSS 8.8
CVE-2019-1350 [HIGH] CVE-2019-1350: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
Debian
CVE-2019-1352: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
vendor_debian·2019·CVSS 8.8
CVE-2019-1352 [HIGH] CVE-2019-1352: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
Debian
CVE-2019-1349: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
vendor_debian·2019·CVSS 8.8
CVE-2019-1349 [HIGH] CVE-2019-1349: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
Debian
CVE-2019-1354: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
vendor_debian·2019·CVSS 8.8
CVE-2019-1354 [HIGH] CVE-2019-1354: git - A remote code execution vulnerability exists when Git for Visual Studio improper...
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.
Scope: local
bookworm: resolved (fixed in 1:2.24.0-2)
bullseye: resolved (fixed in 1:2.24.0-2)
forky: resolved (fixed in 1:2.24.0-2)
sid: resolved (fixed in 1:2.24.0-2)
trixie: resolved (fixed in 1:2.24.0-2)
No detection rules found.
No public exploits indexed.
Qualys
December 2019 Patch Tuesday – 36 Vulns, 7 Critical, Actively Attacked Win32k vuln, Adobe vulns
blogs_qualys·2019-12-10·CVSS 8.8
CVE-2019-1468 [HIGH] December 2019 Patch Tuesday – 36 Vulns, 7 Critical, Actively Attacked Win32k vuln, Adobe vulns
This month’s Patch Tuesday is rather light and addresses 36 vulnerabilities, with only 7 labeled as Critical. Five of the seven Critical vulns are in Git for Visual Studio. The others are for Hyper-V and Win32k. Also, there is one actively attacked “Important” vuln in Win32k. Adobe released patches today covering Acrobat/Reader, ColdFusion, Photoshop, and Brackets.
## Workstation Patches
Win32k patches ( CVE-2019-1468 and CVE-2019-1458 ) should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
Though listed as Important, Microsoft has disclosed that CVE-2019-1458 is actively attacked in the wild.
## Hyper-V Hypervisor Escapes
A remo
Tenable
Microsoft's December 2019 Patch Tuesday Includes Fix for Zero Day Exploited in the Wild (CVE-2019-1458)
blogs_tenable·2019-12-10·CVSS 7.8
[HIGH] Microsoft's December 2019 Patch Tuesday Includes Fix for Zero Day Exploited in the Wild (CVE-2019-1458)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
December 2019 Patch Tuesday - 36 Vulns, 7 Critical, Actively Attacked Win32k vuln, Adobe vulns | Qualys
blogs_qualys·2019-12-10·CVSS 8.8
CVE-2019-1468 [HIGH] December 2019 Patch Tuesday - 36 Vulns, 7 Critical, Actively Attacked Win32k vuln, Adobe vulns | Qualys
This month’s Patch Tuesday is rather light and addresses 36 vulnerabilities, with only 7 labeled as Critical. Five of the seven Critical vulns are in Git for Visual Studio. The others are for Hyper-V and Win32k. Also, there is one actively attacked “Important” vuln in Win32k. Adobe released patches today covering Acrobat/Reader, ColdFusion, Photoshop, and Brackets.
### Workstation Patches
Win32k patches (CVE-2019-1468 and CVE-2019-1458) should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
Though listed as Important, Microsoft has disclosed that CVE-2019-1458 is actively attacked in the wild.
### Hyper-V Hypervisor Escapes
A remo
Bugzilla
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
bugzilla·2020-04-29·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
An issue was discovered in libgit2 where path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is the libgit2 variant of CVE-2019-1352.
References:
https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj
https://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01
https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cb
https://github.com/libgit2/libgit2/releases/tag/v0.28.4
https://github.com/libgit2/libgit2/releases/tag/v0.99.0
Discussion:
Statement:
Even if the code in the versions of libgit2 as
Bugzilla
CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-1352 [HIGH] CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
bugzilla·2019-12-11·CVSS 8.8
CVE-2019-1352 [HIGH] CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
CVE-2019-1352 git: Files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
Git was unaware of NTFS Alternate Data Streams, allowing files inside the .git/ directory to be overwritten during a clone.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
Discussion:
Created git tracking bugs for this issue:
Affects: fedora-all [bug 1781964]
---
oss-security mailing list reference:
https://www.openwall.com/lists/oss-security/2019/12/13/1
---
External References:
https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj
---
Upstream fix:
https://github.com/git/git/commit/7c3745fc6185495d5765628b4dfe1bd2c25a2981
---
Statement:
Even if the code in the versions of git as
Bugzilla
CVE-2019-1349 git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
bugzilla·2019-12-09·CVSS 8.8
CVE-2019-1349 [HIGH] CVE-2019-1349 git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
CVE-2019-1349 git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/
When using submodule paths that refer to the same file system entity (e.g. using the NTFS Alternate Data Streams attack mentioned in CVE-2019-1352 where files would be written to the `.git/` directory using a synonymous directory name), it was possible to "squat" on the `git~1` shortname on NTFS drives, opening attacks via `git~2`. This also affects Git when run as a Linux application inside the Windows Subsystem for Linux.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
Discussion:
Created git tracking bugs for this issue:
Affects: fedora-all [bug 1781957]
---
oss-security mailing list refe
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2020:0228https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1352https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2020:0228https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1352https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/https://security.gentoo.org/glsa/202003-30
2020-01-24
Published