Input validation error in Git - CVE-2019-1352
Published: December 10, 2019 / Updated: December 11, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input within the Git for Visual Studio. A remote attacker can convince the user to clone a malicious repo and execute arbitrary code on the target system.
Affected software
Amazon Linux AMI
Gentoo Linux
Arch Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
openSUSE Leap
openEuler
Fedora
libgit2 (Alpine package)
libgit2-1.0 (Alpine package)
git (Alpine package)
git (Ubuntu package)
git (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
libgit2-devel
libgit2-debugsource
libgit2-26-32bit-debuginfo
libgit2-26-32bit
libgit2-26
libgit2-26-debuginfo
libgit2-debuginfo
libgit2
git
Red Hat Software Collections
Visual Studio
How to mitigate CVE-2019-1352
libgit2 (Alpine package) - update to 0.28.4-r0
libgit2-1.0 (Alpine package) - update to 1.0.1-r1
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.7, 1:2.17.1-1ubuntu0.5, 1:2.20.1-2ubuntu1.19.04.1, 1:2.20.1-2ubuntu1.19.10.1
git (Debian package) - addressed in versions 1:2.11.0-3+deb9u5, 1:2.20.1-2+deb10u1
git (Alpine package) - addressed in versions 2.15.4-r0, 2.18.2-r0
libgit2-devel - update to 0.26.8-150000.3.15.1
libgit2-debugsource - update to 0.26.8-150000.3.15.1
libgit2-26-32bit-debuginfo - update to 0.26.8-150000.3.15.1
libgit2-26-32bit - update to 0.26.8-150000.3.15.1
libgit2-26 - update to 0.26.8-150000.3.15.1
libgit2-26-debuginfo - update to 0.26.8-150000.3.15.1
libgit2-devel - update to 0.27.8-5
libgit2-debugsource - update to 0.27.8-5
libgit2-debuginfo - update to 0.27.8-5
libgit2 - update to 0.27.8-5
libgit2 - update to 0.28.4-1.fc31
git - addressed in versions 2.21.1-1.fc30, 2.24.1-1.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Microsoft Git for Visual Studio
- Amazon Linux AMI update for git
- Debian update for git
- Ubuntu update for Git
- Multiple vulnerabilities in Git
- Arch Linux update for git
- Arch Linux update for libgit2
- Red Hat update for git
- Red Hat update for rh-git218-git
- OpenSUSE Linux update for git
- Red Hat update for git
- Gentoo update for Git
- OpenSUSE Linux update for git
- Input validation error in git (Alpine package)
- Input validation error in libgit2 (Alpine package)
- Input validation error in libgit2-1.0 (Alpine package)
- SUSE update for libgit2
- openEuler update for libgit2
- Fedora 30 update for git
- Fedora 31 update for git
- Fedora 31 update for libgit2