Improper Input Validation
Affecting git package, versions <1:2.20.1-2+deb10u1
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
References
CVSS Score
3.3
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityLow
-
AvailabilityNone
- CVE
- CVE-2019-1348
- Snyk ID
- SNYK-DEBIAN10-GIT-537140
- Disclosed
- 24 Jan, 2020
- Published
- 10 Dec, 2019