CVE-2019-1349: Input Validation
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
Other sources
When using submodule paths that refer to the same file system entity (e.g. using the NTFS Alternate Data Streams attack mentioned in CVE-2019-1352 where files would be written to the .git/ directory using a synonymous directory name), it was possible to "squat" on the git~1 shortname on NTFS drives, opening attacks via git~2. This also affects Git when run as a Linux application inside the Windows Subsystem for Linux.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1349?
CVE-2019-1349 is classified as a remote code execution vulnerability.
How do I fix CVE-2019-1349?
To fix CVE-2019-1349, update Git to the recommended versions listed in the advisory.
Which software is affected by CVE-2019-1349?
CVE-2019-1349 affects Git for Visual Studio and certain versions of Git on Debian and Red Hat.
Can CVE-2019-1349 allow an attacker to execute commands remotely?
Yes, CVE-2019-1349 can allow an attacker to execute arbitrary commands on the vulnerable system.
What are the potential impacts of CVE-2019-1349?
The potential impacts of CVE-2019-1349 include unauthorized access and control over the affected systems.