发布时间: 2022年8月5日
修改时间: 2022年8月5日
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows installer execute a binary into `C: mingw64 bin git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C: mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C: `.
NVD | openEuler | |
---|---|---|
CVSS评分 | 7.3 | 8.2 |
Attack Vector | Local | Local |
Attack Complexity | Low | Low |
Privileges Required | Low | Low |
User Interaction | Required | Required |
Scope | Unchanged | Changed |
Confidentiality | High | High |
Integrity | High | High |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-1820 | Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows installer execute a binary into `C: mingw64 bin git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C: mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C: `. | 2022年8月5日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | git | Unaffected |
KY3.4-5 | git | Unaffected |
KY3.5.1 | git | Unaffected |