VYPR

rpm package

suse/git&distro=SUSE Linux Enterprise Server 12 SP5

pkg:rpm/suse/git&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Vulnerabilities (25)

  • CVE-2019-1351Jan 24, 2020
    affected < 2.12.3-27.22.1fixed 2.12.3-27.22.1

    A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.

  • CVE-2019-1350Jan 24, 2020
    affected < 2.12.3-27.22.1fixed 2.12.3-27.22.1

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1349Jan 24, 2020
    affected < 2.12.3-27.22.1fixed 2.12.3-27.22.1

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1387Dec 18, 2019
    affected < 2.12.3-27.22.1fixed 2.12.3-27.22.1

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attac

  • CVE-2019-19604Dec 10, 2019
    affected < 2.12.3-27.22.1fixed 2.12.3-27.22.1

    Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.

Page 2 of 2