A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1351 | patch vendor advisory |
https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/ | |
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202003-30 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html | vendor advisory |