Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1348

Опубликовано: 10 дек. 2019
Источник: redhat
CVSS3: 3.3

Описание

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

A flaw was found in the git fast-import command where it provides the export-marks feature that may unexpectedly overwrite arbitrary paths. An attacker can abuse this flaw if they can control the input passed to the fast-import command by using the export-marks feature and overwrite arbitrary files, but would not have complete control on the content of the file.

Меры по смягчению последствий

Avoid running git fast-import on untrusted input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitOut of support scope
Red Hat Enterprise Linux 7gitWill not fix
Red Hat Fuse 7camel-gitNot affected
Red Hat JBoss Fuse 6camel-gitNot affected
Red Hat Enterprise Linux 8gitFixedRHSA-2019:435619.12.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsgitFixedRHSA-2020:022827.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1781953git: Arbitrary path overwriting via export-marks in-stream command feature

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

CVSS3: 3.3
nvd
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

CVSS3: 3.3
debian
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v ...

CVSS3: 4.4
fstec
почти 6 лет назад

Уязвимость опции быстрого импорта --export-marks распределенной системы управления версиями Git, позволяющая нарушителю вызвать отказ в обслуживании и оказать воздействие на целостность данных

oracle-oval
больше 5 лет назад

ELSA-2019-4356: git security update (IMPORTANT)

3.3 Low

CVSS3