Lucene search

K
freebsdFreeBSD21F12DE8-B1DB-11ED-B0F4-002590F2A714
HistoryFeb 14, 2023 - 12:00 a.m.

git -- "git apply" overwriting paths outside the working tree

2023-02-1400:00:00
vuxml.freebsd.org
22
git apply
crafted input
working tree
overwrite
unix
git team reports

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

45.7%

git team reports:

By feeding a crafted input to “git apply”, a path outside the
working tree can be overwritten as the user who is running “git
apply”.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgit< 2.39.2UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

45.7%