GitHubÐÞ¸´9¸öGitÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1348£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1349£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1350£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1351£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1352£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1353£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1354£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-1387£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-19604£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Git 2.24¼°ÒÔϰ汾
Îó²î¸ÅÊö
GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÂþÑÜʽ°æ±¾¿ØÖÆÏµÍ³¡£¡£¡£ËüÐÞ¸´ÁËÈçϾŸöÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2019-1350£¬£¬£¬£¬£¬£¬CVE-2019-1351£¬£¬£¬£¬£¬£¬CVE-2019-1352£¬£¬£¬£¬£¬£¬CVE-2019-1353ºÍCVE-2019-1354ÊÇWindowsÌØ¶¨µÄÎó²î£¬£¬£¬£¬£¬£¬ÔÚ¿Ë¡²»ÊÜÐÅÈεĴ洢¿âʱ¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£CVE-2019-1352¿ÉÒÔÓ°Ïì·ÇWindowsÓû§£¬£¬£¬£¬£¬£¬µ«Ìõ¼þÊDZØÐè¹ÒÔØNTFS¾í¡£¡£¡£
CVE-2019-1348
git fast-importµÄ--export-marksÑ¡ÏîҲͨ¹ýÒÔÏ·½·¨¹ûÕæÁ÷ÄÚÏÂÁЧexport-marks = ...£¬£¬£¬£¬£¬£¬ËüÔÊÐíÁýÕÖí§Òâ·¾¶¡£¡£¡£
CVE-2019-1349
ÔÚijЩÇéÐÎÏÂÒԵݹ鷽·¨¿Ë¡×ÓÄ£¿£¿£¿£¿£¿éʱGit¿ÉÄܱ»ÓÕÆÁ½´ÎʹÓÃÏàͬµÄGitĿ¼¡£¡£¡£
CVE-2019-1350
ÏÂÁîÐвÎÊýÒýÓò»×¼È·ÔÊÐíÔ¶³Ì´úÂëÓëSSH URLÒ»ÆðÔڵݹé¿Ë¡ʱ´úÖ´ÐС£¡£¡£
CVE-2019-1351
ÎïÀíÇý¶¯Æ÷ÉÏΨһÔÊÐíʹÓõÄÇý¶¯Æ÷ºÅ WindowsÊÇÃÀ¹úÓ¢Óï×Öĸ£¬£¬£¬£¬£¬£¬´ËÏÞÖÆ²»ÊÊÓÃÓÚͨ¹ýsubst<letter>:<path>·ÖÅɵÄÐéÄâÇý¶¯Æ÷¡£¡£¡£Git½«´ËÀà·¾¶ÎóÒÔΪÊÇÏà¶Ô·¾¶£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÔÚ¿Ë¡ʱдÔÚÊÂÇéÊ÷Íⲿ¡£¡£¡£
CVE-2019-1352
Git²»ÖªµÀNTFS±¸ÓÃÊý¾ÝÁ÷£¬£¬£¬£¬£¬£¬¿Ë¡ʱ´úÔÊÐíÎļþÁýÕÖ.git/Ŀ¼¡£¡£¡£
CVE-2019-1353
ÔÚLinuxµÄWindows×ÓϵͳÖÐÔËÐÐGitʱ£¨Ò²³ÆÎª¡° WSL¡±£©£¬£¬£¬£¬£¬£¬ÔÚͨÀýWindowsÇý¶¯Æ÷ÉÏ»á¼ûÊÂÇéĿ¼ʱ£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκÎNTFS±£»£»£»£»¤´¦Óڻ״̬¡£¡£¡£
CVE-2019-1354
Linux / UnixÉϵÄÎļþÃû¿ÉÒÔ°üÀ¨·´Ð±¸Ü¡£¡£¡£ÔÚWindowsÉÏ£¬£¬£¬£¬£¬£¬·´Ð±¸ÜÊÇĿ¼ÍÑÀë·û¡£¡£¡£ Git²¢Ã»ÓоܾøÓÃÕâÑùµÄÎļþÃûд³ö¸ú×ÙÎļþ¡£¡£¡£
CVE-2019-1387
µÝ¹é¿Ë¡Ŀ½ñÊÜÒÔÏÂÎó²îµÄÓ°Ï죺×ÓÄ£¿£¿£¿£¿£¿éÃû³ÆÑéÖ¤¹ýÓÚ¿íËÉÔì³ÉµÄ£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýµÝ¹é¿Ë¡ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÀ´¾ÙÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£
CVE-2019-19604
¡°Git×ÓÄ£¿£¿£¿£¿£¿é¸üС±²Ù×÷¿ÉÒÔÔËÐжñÒâ´æ´¢¿âµÄ.gitmodulesÎļþÖÐÕÒµ½µÄÏÂÁî¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.blog/2019-12-10-multiple-git-vulnerabilities-in-2-24-and-older/¡£¡£¡£
²Î¿¼Á´½Ó
https://www.cbronline.com/news/git-project-patches