QID 354769
Date Published: 2023-02-28
QID 354769: Amazon Linux Security Advisory for git : ALAS2-2023-1943
a flaw was found in the git fast-import command where it provides the export-marks feature that may unexpectedly overwrite arbitrary paths.
An attacker can abuse this flaw if they can control the input passed to the fast-import command by using the export-marks feature and overwrite arbitrary files, but would not have complete control on the content of the file. (
( CVE-2019-1348) an improper input validation flaw was discovered in git in the way it handles git submodules.
A remote attacker could abuse this flaw to trick a victim user into recursively cloning a malicious repository, which, under certain circumstances, could fool git into using the same git directory twice and potentially cause remote code execution. (
( CVE-2019-1349) a remote code execution vulnerability exists when git for visual studio improperly sanitizes input, aka git for visual studio remote code execution vulnerability.
This( CVE id is unique from( CVE-2019-1349,( CVE-2019-1352,( CVE-2019-1354,( CVE-2019-1387. (
( CVE-2019-1350) a tampering vulnerability exists when git for visual studio improperly handles virtual drive paths, aka git for visual studio tampering vulnerability. (
( CVE-2019-1351) a remote code execution vulnerability exists when git for visual studio improperly sanitizes input, aka git for visual studio remote code execution vulnerability.
This( CVE id is unique from( CVE-2019-1349,( CVE-2019-1350,( CVE-2019-1354,( CVE-2019-1387. (
( CVE-2019-1352) an issue was found in git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
This( CVE id is unique from( CVE-2019-1349,( CVE-2019-1350,( CVE-2019-1352,( CVE-2019-1387. (
( CVE-2019-19604)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2-2023-1943 -
alas.aws.amazon.com/AL2/ALAS-2023-1943.html
CVEs related to QID 354769
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2023-1943 | amazon linux 2 |
|