• CVE-2025-48386

发布时间: 2025年7月11日

修改时间: 2025年7月18日

概要

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The wincred credential helper uses a static buffer (target) as a unique key for storing and comparing against internal storage. This credential helper does not properly bounds check the available space remaining in the buffer before appending to it with wcsncat(), leading to potential buffer overflows. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Local
CVSS评分 N/A 6.3
Attack Complexity Low
Privileges Required None
Scope Changed
Integrity None
User Interaction Required
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2716 git security update 2025年8月1日

影响产品

产品 状态
KY3.4-5 git Fixed
V6 git Fixed
KY3.5.3 git Fixed
KY3.5.2 git Fixed