ืคื’ื™ืขื•ื™ื•ืช ื‘-Git ื‘ืขืช ืฉื™ื‘ื•ื˜ ืชืช-ืžื•ื“ื•ืœื™ื ื•ืฉื™ืžื•ืฉ ื‘ืžืขื˜ืคืช git

ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืžืขืจื›ืช ื‘ืงืจืช ื”ืžืงื•ืจื•ืช ื”ืžื‘ื•ื–ืจืช Git 2.38.1, 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3 ื•- 2.37.4 ืคื•ืจืกืžื•, ืืฉืจ ืชื™ืงื ื• ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช, ื”ืžื•ืคื™ืขื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืคืงื•ื“ื” "ื’ื™t clone" ื‘ืžืฆื‘ "-recurse-submodules" ืขื ืžืื’ืจื™ื ืœื ืžืกื•ืžื ื™ื ื•ื‘ืฉื™ืžื•ืฉ ื‘ืžืฆื‘ ื”ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ "git shell". ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD.

  • CVE-2022-39253 - ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ื”ืฉื•ืœื˜ ื‘ืชื•ื›ืŸ ื”ืžืื’ืจ ื”ืžืฉื•ื‘ื˜ ืœืงื‘ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืกื•ื“ื™ื™ื ื‘ืžืขืจื›ืช ื”ืžืฉืชืžืฉ ืขืœ ื™ื“ื™ ื”ืฆื‘ืช ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ืœืงื‘ืฆื™ ืขื ื™ื™ืŸ ื‘ืกืคืจื™ื™ืช $GIT_DIR/objects ืฉืœ ื”ืžืื’ืจ ื”ืžืฉื•ื‘ื˜. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืขืช ืฉื™ื‘ื•ื˜ ืžืงื•ืžื™ (ื‘ืžืฆื‘ "--local", ื‘ืฉื™ืžื•ืฉ ื›ืืฉืจ ื ืชื•ื ื™ ื”ื™ืขื“ ื•ื”ืžืงื•ืจ ืฉืœ ื”ืฉื™ื‘ื•ื˜ ื ืžืฆืื™ื ื‘ืื•ืชื” ืžื—ื™ืฆื”) ืื• ื‘ืขืช ืฉื™ื‘ื•ื˜ ืžืื’ืจ ื–ื“ื•ื ื™ ืืจื•ื– ื›ืชืช-ืžื•ื“ื•ืœ ื‘ืžืื’ืจ ืื—ืจ (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืจืงื•ืจืกื™ื‘ื™ืช ื›ื•ืœืœ ืชืช-ืžื•ื“ื•ืœื™ื ืขื ื”ืคืงื•ื“ื” "git clone" --recurse-submodules").

    ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ืขื•ื‘ื“ื” ืฉื‘ืžืฆื‘ ื”ืฉื™ื‘ื•ื˜ "--local", git ืžืขื‘ื™ืจ ืืช ื”ืชื•ื›ืŸ ืฉืœ $GIT_DIR/objects ืœืกืคืจื™ื™ืช ื”ื™ืขื“ (ื™ืฆื™ืจืช ืงื™ืฉื•ืจื™ื ืงืฉื™ื—ื™ื ืื• ืขื•ืชืงื™ื ืฉืœ ืงื‘ืฆื™ื), ืชื•ืš ื‘ื™ืฆื•ืข ื”ืคื ื™ื™ื” ืฉืœ ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื (ื›ืœื•ืžืจ, ื›ืžื• ื›ืชื•ืฆืื” ืžื›ืš, ืงื™ืฉื•ืจื™ื ืœื ืกืžืœื™ื™ื ืžื•ืขืชืงื™ื ืœืกืคืจื™ื™ืช ื”ื™ืขื“, ืืš ื™ืฉื™ืจื•ืช ื”ืงื‘ืฆื™ื ืฉืืœื™ื”ื ื”ืงื™ืฉื•ืจื™ื ืžืคื ื™ื). ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ืคื’ื™ืขื•ืช, ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ git ืื•ืกืจื•ืช ืฉื™ื‘ื•ื˜ ืฉืœ ืžืื’ืจื™ื ื‘ืžืฆื‘ "--local" ื”ืžื›ื™ืœื™ื ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ื‘ืกืคืจื™ื™ืช $GIT_DIR/objects. ื‘ื ื•ืกืฃ, ืขืจืš ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืคืจืžื˜ืจ protocol.file.allow ืฉื•ื ื” ืœ"ืžืฉืชืžืฉ", ืžื” ืฉื”ื•ืคืš ืืช ืคืขื•ืœื•ืช ื”ืฉื™ื‘ื•ื˜ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ file:// ืœื ื‘ื˜ื•ื—ื•ืช.

  • CVE-2022-39260 - ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” split_cmdline() ื”ืžืฉืžืฉืช ื‘ืคืงื•ื“ื” "git shell". ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื” ื›ื“ื™ ืœืชืงื•ืฃ ืžืฉืชืžืฉื™ื ืฉื™ืฉ ืœื”ื "git shell" ื›ืžืขื˜ืคืช ื”ื›ื ื™ืกื” ืฉืœื”ื ื•ืฉืžืฆื‘ ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ ืžื•ืคืขืœ (ื ื•ืฆืจ ืงื•ื‘ืฅ $HOME/git-shell-commands). ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืžืขืจื›ืช ื‘ืขืช ืฉืœื™ื—ืช ืคืงื•ื“ื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“ ื‘ื’ื•ื“ืœ ืฉืœ ื™ื•ืชืจ ืž-2 ื’'ื™ื’ื”-ื‘ื™ื™ื˜.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”