ืขื“ื›ื•ืŸ Git ืขื 8 ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืžืขืจื›ืช ื‘ืงืจืช ื”ืžืงื•ืจ ื”ืžื‘ื•ื–ืจ Git 2.24.1, 2.23.1, 2.22.2, 2.21.1, 2.20.2, 2.19.3, 2.18.2, 2.17.3, 2.16.6, 2.15.4 ื•-2.14.62.24.1 XNUMX, ืืฉืจ ืชื™ืงืŸ ืคื’ื™ืขื•ื™ื•ืช ืฉืืคืฉืจื• ืœืชื•ืงืฃ ืœืฉื›ืชื‘ ื ืชื™ื‘ื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื, ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืื• ืœื”ื—ืœื™ืฃ ืงื‘ืฆื™ื ื‘ืกืคืจื™ื™ืช ".git/". ืจื•ื‘ ื”ื‘ืขื™ื•ืช ืฉื–ื•ื”ื• ืขืœ ื™ื“ื™ ื”ืขื•ื‘ื“ื™ื
Microsoft Security Response Center, ื—ืžืฉ ืžืชื•ืš ืฉืžื•ื ื” ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ื”ืŸ ืกืคืฆื™ืคื™ื•ืช ืœืคืœื˜ืคื•ืจืžืช Windows.

  • CVE-2019-1348 - ืคืงื•ื“ืช ืกื˜ืจื™ืžื™ื ื’ "ืคื™ืฆ'ืจ ื™ื™ืฆื•ื-ืกื™ืžื ื™ื=ื ืชื™ื‘"ื”ื™ื ืžืืคืฉืจืช ื›ืชื•ื‘ ืชื•ื•ื™ื•ืช ืœืกืคืจื™ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช, ื‘ื”ืŸ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื”ื—ืœื™ืฃ ื ืชื™ื‘ื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœืช "ื™ื™ื‘ื•ื โ€‹โ€‹ืžื”ื™ืจ ืฉืœ git" ืขื ื ืชื•ื ื™ ืงืœื˜ ืœื ืžืกื•ืžื ื™ื.
  • CVE-2019-1350 - ื‘ืจื™ื—ื” ืœื ื ื›ื•ื ื” ืฉืœ ืืจื’ื•ืžื ื˜ื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืžืจื—ื•ืง ืฉืœ ืงื•ื“ ืชื•ืงืฃ ื‘ืžื”ืœืš ืฉื™ื‘ื•ื˜ ืจืงื•ืจืกื™ื‘ื™ ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ืช ื”ืืชืจ ssh://. ื‘ืคืจื˜, ืืจื’ื•ืžื ื˜ื™ื ื‘ืจื™ื—ื” ืฉื”ืกืชื™ื™ืžื• ื‘ืงื• ื ื˜ื•ื™ ืื—ื•ืจื™ (ืœื“ื•ื’ืžื”, "ืžื‘ื—ืŸ \") ื˜ื•ืคืœื• ื‘ืฆื•ืจื” ืฉื’ื•ื™ื”. ื‘ืžืงืจื” ื–ื”, ื‘ืขืช ืžืกื’ื•ืจ ื˜ื™ืขื•ืŸ ืขื ืžืจื›ืื•ืช ื›ืคื•ืœื•ืช, ื”ืฆื™ื˜ื•ื˜ ื”ืื—ืจื•ืŸ ื”ื™ื” ื‘ืจื™ื—ื”, ืžื” ืฉืืคืฉืจ ืœืืจื’ืŸ ืืช ื”ื—ืœืคืช ื”ืืคืฉืจื•ื™ื•ืช ืฉืœืš ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื”.
  • CVE-2019-1349 - ื‘ืขืช ืฉื™ื‘ื•ื˜ ืจืงื•ืจืกื™ื‘ื™ ืฉืœ ืชืช-ืžื•ื“ื•ืœื™ื ("clone -recurse-submodules") ื‘ืกื‘ื™ื‘ืช Windows ื‘ืชื ืื™ื ืžืกื•ื™ืžื™ื ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืคืขื™ืœื™ื ืืช ื”ืฉื™ืžื•ืฉ ื‘ืื•ืชื” ืกืคืจื™ื™ืช git ืคืขืžื™ื™ื (.git, git~1, git~2 ื•-git~N ืžื•ื›ืจื™ื ื›ืกืคืจื™ื™ื” ืื—ืช ื‘-NTFS, ืื‘ืœ ืžืฆื‘ ื–ื” ื ื‘ื“ืง ืจืง ืขื‘ื•ืจ git~1), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืืจื’ืŸ ื›ืชื™ื‘ื” ืœืกืคืจื™ื™ื” ". git". ื›ื“ื™ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœื•, ืชื•ืงืฃ, ืœืžืฉืœ, ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ ืืช ื”ืกืงืจื™ืคื˜ ืฉืœื• ื“ืจืš ื”ืžื˜ืคืœ ืฉืœืื—ืจ ื”ืชืฉืœื•ื ื‘ืงื•ื‘ืฅ .git/config.
  • CVE-2019-1351 - ื”ืžื˜ืคืœ ืœืฉืžื•ืช ื›ื•ื ื ื™ ืื•ืชื™ื•ืช ื‘ื ืชื™ื‘ื™ Windows ื‘ืขืช ืชืจื’ื•ื ื ืชื™ื‘ื™ื ื›ืžื• "C:\" ืชื•ื›ื ืŸ ืจืง ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืžื–ื”ื™ื ืœื˜ื™ื ื™ื™ื ืฉืœ ืื•ืช ืื—ืช, ืืš ืœื ืœืงื— ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืืคืฉืจื•ืช ืœื™ืฆื•ืจ ื›ื•ื ื ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืฉื”ื•ืงืฆื• ื‘ืืžืฆืขื•ืช "ืื•ืช subst:path" . ื ืชื™ื‘ื™ื ื›ืืœื” ืœื ื˜ื•ืคืœื• ื›ืืœ ืžื•ื—ืœื˜ื™ื, ืืœื ื›ื ืชื™ื‘ื™ื ื™ื—ืกื™ื™ื, ืžื” ืฉืื™ืคืฉืจ, ื‘ืขืช ืฉื™ื‘ื•ื˜ ืžืื’ืจ ื–ื“ื•ื ื™, ืœืืจื’ืŸ ืจืฉื•ืžื” ื‘ืกืคืจื™ื™ื” ืฉืจื™ืจื•ืชื™ืช ืžื—ื•ืฅ ืœืขืฅ ืกืคืจื™ื•ืช ื”ืขื‘ื•ื“ื” (ืœื“ื•ื’ืžื”, ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืกืคืจื™ื ืื• ืชื•ื•ื™ Unicode ื‘ื“ื™ืกืง ืฉื - "1:\what\the\ hex.txt" ืื• "รค:\tschibรคt.sch").
  • CVE-2019-1352 - ื‘ืขืช ืขื‘ื•ื“ื” ืขืœ ืคืœื˜ืคื•ืจืžืช Windows, ื”ืฉื™ืžื•ืฉ ื‘ื–ืจืžื™ ื ืชื•ื ื™ื ื—ืœื•ืคื™ื™ื ื‘-NTFS, ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืชื›ื•ื ื” ":stream-name:stream-type" ืœืฉื ื”ืงื•ื‘ืฅ, ืžื•ึผืชึธืจ ื”ื—ืœืฃ ืงื‘ืฆื™ื ื‘ืกืคืจื™ื™ืช ".git/" ื‘ืขืช ืฉื™ื‘ื•ื˜ ืžืื’ืจ ื–ื“ื•ื ื™. ืœื“ื•ื’ืžื”, ื”ืฉื ".git::$INDEX_ALLOCATION" ื‘-NTFS ื˜ื•ืคืœ ื›ืงื™ืฉื•ืจ ื—ื•ืงื™ ืœืกืคืจื™ื™ืช ".git".
  • CVE-2019-1353 - ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Git ื‘ืกื‘ื™ื‘ืช WSL (Windows Subsystem for Linux) ื‘ืขืช ื’ื™ืฉื” ืœืกืคืจื™ื™ืช ื”ืขื‘ื•ื“ื” ืœื ื‘ืฉื™ืžื•ืฉ ื”ื’ื ื” ืžืคื ื™ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืฉืžื•ืช ื‘-NTFS (ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ืชืจื’ื•ื ืฉืžื•ืช FAT ื”ื™ื• ืืคืฉืจื™ื•ืช, ืœืžืฉืœ, ื ื™ืชืŸ ื”ื™ื” ืœื’ืฉืช ืœ-".git" ื“ืจืš ืกืคืจื™ื™ืช "git~1").
  • CVE-2019-1354 -
    ื”ื–ื“ืžื ื•ืช ื›ื•ืชื‘ ืœืกืคืจื™ื™ืช ".git/" ื‘ืคืœื˜ืคื•ืจืžืช Windows ื‘ืขืช ืฉื™ื‘ื•ื˜ ืžืื’ืจื™ื ื–ื“ื•ื ื™ื™ื ื”ืžื›ื™ืœื™ื ืงื‘ืฆื™ื ืขื ื ื˜ื•ื™ ืื—ื•ืจื™ ื‘ืฉื (ืœื“ื•ื’ืžื”, "a\b"), ื”ืžืงื•ื‘ืœ ื‘-Unix/Linux, ืืš ืžืงื•ื‘ืœ ื›ื—ืœืง ืž- ื”ื ืชื™ื‘ ื‘-Windows.

  • CVE-2019-1387 - ื‘ื“ื™ืงื” ืœื ืžืกืคืงืช ืฉืœ ืฉืžื•ืช ืชืช-ืžื•ื“ื•ืœื™ื ืขืœื•ืœื” ืœืฉืžืฉ ื›ื“ื™ ืœืืจื’ืŸ ื”ืชืงืคื•ืช ืžืžื•ืงื“ื•ืช, ืฉืื ื™ืฉื•ื‘ื˜ื• ื‘ืื•ืคืŸ ืจืงื•ืจืกื™ื‘ื™, ืขืœื•ืœื•ืช ืœื”ื™ื•ืช ื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืงื•ื“ ืฉืœ ื”ืชื•ืงืฃ. Git ืœื ืžื ืข ื™ืฆื™ืจืช ืกืคืจื™ื™ืช ืชืช-ืžื•ื“ื•ืœ ื‘ืชื•ืš ืกืคืจื™ื™ืช ืชืช-ืžื•ื“ื•ืœ ืื—ืจ, ืžื” ืฉื‘ืจื•ื‘ ื”ืžืงืจื™ื ืจืง ื™ื•ื‘ื™ืœ ืœื‘ืœื‘ื•ืœ, ืืš ืœื ืžื ืข ื‘ืคื•ื˜ื ืฆื™ื” ืืช ื”ื—ืœืคืช ื”ืชื•ื›ืŸ ืฉืœ ืžื•ื“ื•ืœ ืื—ืจ ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืฉื™ื‘ื•ื˜ ื”ืจืงื•ืจืกื™ (ืœื“ื•ื’ืžื”, ืกืคืจื™ื•ืช ื”ืชืช-ืžื•ื“ื•ืœื™ื "hipo" ื•-"hipo/hooks" ืžืžื•ืงืžื™ื ื›-" .git/modules/hippo/" ื•-".git/modules/hipo/hooks/", ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืกืคืจื™ื™ืช ื”-hooks ื‘ื”ื™ืคื•ืคื•ื˜ื ื‘ื ืคืจื“ ื›ื“ื™ ืœืืจื— ื”ื•ืงืก ืฉื”ื•ืคืขืœื•.

ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ Windows ืœืขื“ื›ืŸ ืžื™ื“ ืืช ื’ืจืกืช Git ืฉืœื”ื, ื•ืœื”ื™ืžื ืข ืžืฉื™ื‘ื•ื˜ ืžืื’ืจื™ื ืœื ืžืื•ืžืชื™ื ืขื“ ืœืขื“ื›ื•ืŸ. ืื ืขื“ื™ื™ืŸ ืœื ื ื™ืชืŸ ืœืขื“ื›ืŸ ื‘ื“ื—ื™ืคื•ืช ืืช ื’ืจืกืช Git, ืื– ื›ื“ื™ ืœื”ืคื—ื™ืช ืืช ื”ืกื™ื›ื•ืŸ ืœื”ืชืงืคื”, ืžื•ืžืœืฅ ืœื ืœื”ืคืขื™ืœ "git clone โ€”recurse-submodules" ื•-"git submodule update" ืขื ืžืื’ืจื™ื ืœื ืžืกื•ืžื ื™ื, ืœื ืœื”ืฉืชืžืฉ ื‘-"git ืžื”ื™ืจ-ื™ื™ื‘ื•ื" ืขื ื–ืจืžื™ ืงืœื˜ ืœื ืžืกื•ืžื ื™ื, ื•ืœื ืœืฉื›ืคืœ ืžืื’ืจื™ื ืœืžื—ื™ืฆื•ืช ืžื‘ื•ืกืกื•ืช NTFS.

ืœืžืขืŸ ืื‘ื˜ื—ื” ื ื•ืกืคืช, ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืื•ืกืจื•ืช ื’ื ืขืœ ืฉื™ืžื•ืฉ ื‘ืžื‘ื ื™ื ื‘ืฆื•ืจืช "submodule.{name}.update=!command" ื‘-.gitmodules. ืขื‘ื•ืจ ื”ืคืฆื•ืช, ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื“ืคื™ื ื“ื‘ื™ืืŸ,ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, SUSE/openSUSE, ืคื“ื•ืจื”, ืงืฉืช, ALT, FreeBSD.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”