A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1351 | Patch Vendor Advisory |
https://public-inbox.org/git/xmqqr21cqcn9.fsf@gitster-ct.c.googlers.com/ | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html | Third Party Advisory |
https://security.gentoo.org/glsa/202003-30 | |
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html |
Information
Published : 2020-01-24 13:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-1351
Mitre link : CVE-2019-1351
JSON object : View
CWE
CWE-706
Use of Incorrectly-Resolved Name or Reference
Products Affected
microsoft
- visual_studio_2017
- visual_studio_2019
opensuse
- leap