Input validation error in Git - CVE-2019-1387
Published: December 10, 2019 / Updated: December 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input within the Git for Visual Studio. A remote attacker can convince the user to clone a malicious repo and execute arbitrary code on the target system.
Affected software
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
libgit2 (Alpine package)
libgit2-1.0 (Alpine package)
git (Alpine package)
git (Ubuntu package)
git (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
libgit2
git
Red Hat Software Collections
Visual Studio
OpenManage Network Integration (OMNI)
How to mitigate CVE-2019-1387
libgit2 (Alpine package) - update to 0.28.4-r0
libgit2-1.0 (Alpine package) - update to 1.0.1-r1
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.7, 1:2.17.1-1ubuntu0.5, 1:2.20.1-2ubuntu1.19.04.1, 1:2.20.1-2ubuntu1.19.10.1
git (Debian package) - addressed in versions 1:2.11.0-3+deb9u5, 1:2.20.1-2+deb10u1
git (Alpine package) - addressed in versions 2.15.4-r0, 2.18.2-r0
libgit2 - update to 0.28.4-1.fc31
git - addressed in versions 2.21.1-1.fc30, 2.24.1-1.fc31
OpenManage Network Integration (OMNI) - update to 3.7
External References
Related Security Bulletins
- Multiple vulnerabilities in Microsoft Git for Visual Studio
- Amazon Linux AMI update for git
- Debian update for git
- Ubuntu update for Git
- Multiple vulnerabilities in Git
- Arch Linux update for git
- Arch Linux update for libgit2
- Red Hat update for git
- Red Hat update for rh-git218-git
- Red Hat update for git
- OpenSUSE Linux update for git
- Red Hat update for git
- Gentoo update for Git
- Gentoo update for libgit2
- OpenSUSE Linux update for git
- Input validation error in git (Alpine package)
- Input validation error in libgit2 (Alpine package)
- Input validation error in libgit2-1.0 (Alpine package)
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Fedora 30 update for git
- Fedora 31 update for git
- Fedora 31 update for libgit2