SB2019121086 - Absolute Path Traversal in libgit2 (Alpine package)
Published: December 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Absolute Path Traversal (CVE-ID: CVE-2019-1351)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the Git for Visual Studio improperly handles virtual drive paths. A remote attacker can clone a file using a specially crafted path and write arbitrary files and directories to certain locations on a vulnerable system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=58b4a531b78ab8c0f877521a48ff6c54980277ff
- https://git.alpinelinux.org/aports/commit/?id=0b0f6a3391ac467390d24ad01eaf7105da2ed2a3
- https://git.alpinelinux.org/aports/commit/?id=6b336edb2a6756f1c25574daf608e230ca75160b
- https://git.alpinelinux.org/aports/commit/?id=64bd4efee3d96f4ad333d07b0fabc16320dd2f29
- https://git.alpinelinux.org/aports/commit/?id=330dccaf7a87b0e784100ef5e2fa7f99b72c84d9
- https://git.alpinelinux.org/aports/commit/?id=2379f03a9ab98d2a3845f360063ae03a5b94b2a7
- https://git.alpinelinux.org/aports/commit/?id=c8d39d0ddffc93f57a87b567422cbdbbd707e1f9