Input validation error in Git - CVE-2019-1352

 

Input validation error in Git - CVE-2019-1352

Published: December 10, 2019 / Updated: December 11, 2019


Vulnerability identifier: #VU23492
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1352
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input within the Git for Visual Studio. A remote attacker can convince the user to clone a malicious repo and execute arbitrary code on the target system.


Affected software

Git
Amazon Linux AMI
Gentoo Linux
Arch Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
openSUSE Leap
openEuler
Fedora
libgit2 (Alpine package)
libgit2-1.0 (Alpine package)
git (Alpine package)
git (Ubuntu package)
git (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
libgit2-devel
libgit2-debugsource
libgit2-26-32bit-debuginfo
libgit2-26-32bit
libgit2-26
libgit2-26-debuginfo
libgit2-debuginfo
libgit2
git
Red Hat Software Collections
Visual Studio

How to mitigate CVE-2019-1352

Install updates from vendor's website.

Git - addressed in versions 2.14.6, 2.15.4, 2.16.6, 2.17.3, 2.18.2, 2.19.3, 2.20.2, 2.21.1, 2.22.2, 2.23.1, 2.24.1
libgit2 (Alpine package) - update to 0.28.4-r0
libgit2-1.0 (Alpine package) - update to 1.0.1-r1
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.7, 1:2.17.1-1ubuntu0.5, 1:2.20.1-2ubuntu1.19.04.1, 1:2.20.1-2ubuntu1.19.10.1
git (Debian package) - addressed in versions 1:2.11.0-3+deb9u5, 1:2.20.1-2+deb10u1
git (Alpine package) - addressed in versions 2.15.4-r0, 2.18.2-r0
libgit2-devel - update to 0.26.8-150000.3.15.1
libgit2-debugsource - update to 0.26.8-150000.3.15.1
libgit2-26-32bit-debuginfo - update to 0.26.8-150000.3.15.1
libgit2-26-32bit - update to 0.26.8-150000.3.15.1
libgit2-26 - update to 0.26.8-150000.3.15.1
libgit2-26-debuginfo - update to 0.26.8-150000.3.15.1
libgit2-devel - update to 0.27.8-5
libgit2-debugsource - update to 0.27.8-5
libgit2-debuginfo - update to 0.27.8-5
libgit2 - update to 0.27.8-5
libgit2 - update to 0.28.4-1.fc31
git - addressed in versions 2.21.1-1.fc30, 2.24.1-1.fc31

External References

Related Security Bulletins