CVE-2019-1351 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Arbitrary code execution |
| Description | While the only permitted drive letters for physical drives on Windows are letters of the US-English alphabet, this restriction does not apply to virtual drives assigned via subst <letter>: <path>. Git mistook such paths for relative paths, allowing writing outside of the worktree while cloning. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1074 | git | 2.24.0-1 | 2.24.1-1 | High | Not affected |
| References |
|---|
https://github.com/git/git/commit/f82a97eb9197c1e3768e72648f37ce0ca3233734 https://lkml.org/lkml/2019/12/10/905 |
| Notes |
|---|
Only applicable to Windows |