CVE-2019-1351 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Arbitrary code execution |
Description | While the only permitted drive letters for physical drives on Windows are letters of the US-English alphabet, this restriction does not apply to virtual drives assigned via subst <letter>: <path>. Git mistook such paths for relative paths, allowing writing outside of the worktree while cloning. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1074 | git | 2.24.0-1 | 2.24.1-1 | High | Not affected |
References |
---|
https://github.com/git/git/commit/f82a97eb9197c1e3768e72648f37ce0ca3233734 https://lkml.org/lkml/2019/12/10/905 |
Notes |
---|
Only applicable to Windows |