CVE-2019-1353

EUVD-2019-9911
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
git-scmgit
2.14.0 ≤
𝑥
< 2.14.6
git-scmgit
2.15.0 ≤
𝑥
< 2.15.4
git-scmgit
2.16.0 ≤
𝑥
< 2.16.6
git-scmgit
2.17.0 ≤
𝑥
< 2.17.3
git-scmgit
2.18.0 ≤
𝑥
< 2.18.2
git-scmgit
2.19.0 ≤
𝑥
< 2.19.3
git-scmgit
2.20.0 ≤
𝑥
< 2.20.2
git-scmgit
2.21.0 ≤
𝑥
< 2.21.1
git-scmgit
2.22.0 ≤
𝑥
< 2.22.2
git-scmgit
2.23.0 ≤
𝑥
< 2.23.1
git-scmgit
2.24.0 ≤
𝑥
< 2.24.1
opensuseleap
15.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
git
bookworm
1:2.39.2-1.1
fixed
bookworm (security)
1:2.39.5-0+deb12u1
fixed
bullseye
1:2.30.2-1+deb11u2
fixed
bullseye (security)
1:2.30.2-1+deb11u3
fixed
sid
1:2.45.2-1.1
fixed
trixie
1:2.45.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
git
bionic
Fixed 1:2.17.1-1ubuntu0.5
released
disco
Fixed 1:2.20.1-2ubuntu1.19.04.1
released
eoan
Fixed 1:2.20.1-2ubuntu1.19.10.1
released
trusty
dne
xenial
Fixed 1:2.7.4-0ubuntu1.7
released