Improper Input Validation

Affecting git package, versions <1:2.20.1-2+deb10u1

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

References

CVSS Score

3.3
low severity
  • Attack Vector
    Local
  • Attack Complexity
    Low
  • Privileges Required
    Low
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    None
  • Integrity
    Low
  • Availability
    None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVE
CVE-2019-1348
Snyk ID
SNYK-DEBIAN10-GIT-537140
Disclosed
24 Jan, 2020
Published
10 Dec, 2019