SB2019121089 - Incorrect default permissions in git (Alpine package)
Published: December 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect default permissions (CVE-ID: CVE-2019-1353)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists to due none of the NTFS protections are active when accessing a working directory on a regular Windows drive. A local user with access to the system can view contents of files and directories or modify them.
Note: This vulnerability occurs when running Git in the Windows Subsystem for Linux (also known as "WSL").
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=58b4a531b78ab8c0f877521a48ff6c54980277ff
- https://git.alpinelinux.org/aports/commit/?id=0b0f6a3391ac467390d24ad01eaf7105da2ed2a3
- https://git.alpinelinux.org/aports/commit/?id=6b336edb2a6756f1c25574daf608e230ca75160b
- https://git.alpinelinux.org/aports/commit/?id=64bd4efee3d96f4ad333d07b0fabc16320dd2f29
- https://git.alpinelinux.org/aports/commit/?id=330dccaf7a87b0e784100ef5e2fa7f99b72c84d9
- https://git.alpinelinux.org/aports/commit/?id=2379f03a9ab98d2a3845f360063ae03a5b94b2a7
- https://git.alpinelinux.org/aports/commit/?id=c8d39d0ddffc93f57a87b567422cbdbbd707e1f9