CVE-2019-1352: Input Validation
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.
Other sources
Git was unaware of NTFS Alternate Data Streams, allowing files inside the .git/ directory to be overwritten during a clone.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1352?
CVE-2019-1352 is a remote code execution vulnerability in Git for Visual Studio.
How severe is CVE-2019-1352?
CVE-2019-1352 has a severity rating of 8.8, which is considered critical.
Which software versions are affected by CVE-2019-1352?
CVE-2019-1352 affects Git for Visual Studio 2017 and 2019, as well as certain versions of Git for Debian and Red Hat.
How can I fix CVE-2019-1352?
To fix CVE-2019-1352, you should update to the recommended versions of Git for Visual Studio, Debian, or Red Hat.
Where can I find more information about CVE-2019-1352?
You can find more information about CVE-2019-1352 in the references provided.