摘要:
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows installer execute a binary into `C: mingw64 bin git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C: mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C: `.
安全等级: Low
公告ID: KylinSec-SA-2022-1820
发布日期: 2022年8月5日
关联CVE: CVE-2022-31012
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows installer execute a binary into `C: mingw64 bin git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C: mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C: `.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2022-31012 | KY3.4-4A | git | Unaffected |
CVE-2022-31012 | KY3.4-5 | git | Unaffected |
CVE-2022-31012 | KY3.5.1 | git | Unaffected |