QID 375525
Date Published: 2021-05-06
QID 375525: Cygwin Git Package Remote Code Execution
Cygwin is a Linux-style operating environment for Microsoft Windows.
Cywin git package is affected to execute arbitrary code as soon as the repository is checked out.
Affected Versions:
Cygwin git package version prior to 2.31.1-2
QID Detection Logic (authenticated):
The QID flags if it finds a vulnerable version of the git package in installed file. The location of the file is determined by the key "HKLM\SOFTWARE\Cygwin\setup", value "rootdir". The file is present in the <rootdir>\etc\setup folder.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code as soon as the repository is checked out.
Solution
Upgrade to Cygwin git package to version 2.31.1-2 or later. For more information, please refer to the vendor advisory for affected Cygwin
Vendor References
- CVE-2021-29468 -
cygwin.com/pipermail/cygwin-announce/2021-April/010018.html
CVEs related to QID 375525
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Cygwin Git | Windows |
|