发布时间: 2023年2月24日
修改时间: 2024年10月31日
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Network | Local |
CVSS评分 | 7.5 | 6.2 |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | High | High |
User Interaction | None | None |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1884 | git security update | 2023年2月24日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | git | Fixed |
KY3.4-5A | git | Fixed |
KY3.5.1 | git | Fixed |
KY3.5.2 | git | Fixed |