Skip to main content

Multiple CVE's - Git & Git for Windows


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments

Apologies for the radio silence recently. Had some terrible family news over Christmas and New Year. 

Anyway, the following have been published regarding Git and rated has Critical:

The last CVE is still to be patched and affects Git for Windows. As a workaround, do not use the GUI from clone a repository, especially from untrusted sources.

Therefore, malicious repositories can ship with an aspell.exe in their top-level directory which is executed by Git GUI without giving the user a chance to inspect it first, i.e. running untrusted code.

10 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8506 comments
  • January 18, 2023

Sorry to hear about your news hope all is well now.  Thanks for sharing these latest updates.


marcofabbri
Forum|alt.badge.img+13
  • On the path to Greatness
  • 990 comments
  • January 18, 2023

Sorry to read that @dips

A giant hug from Italy.


marcofabbri
Forum|alt.badge.img+13
  • On the path to Greatness
  • 990 comments
  • January 18, 2023

Talking about that, there’s a full analysis here: https://github.blog/2023-01-17-git-security-vulnerabilities-announced-2/

And here to check about last update: https://about.gitlab.com/update/

Note: GitLab releases have skipped 15.7.4, 15.6.5, and 15.5.8.


Geoff Burke
Forum|alt.badge.img+22
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • January 18, 2023

Sorry to hear that as well Dips. Stay Strong!


JMeixner
Forum|alt.badge.img+17
  • On the path to Greatness
  • 2650 comments
  • January 18, 2023

Sorry to hear this @dips. All the best.


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • 1394 comments
  • January 18, 2023

Sorry to hear this @dips. Stay strong!


Forum|alt.badge.img+4
  • Experienced User
  • 576 comments
  • January 19, 2023

Sorry to hear .. hope all good now !


Madi.Cristil
Forum|alt.badge.img+8
  • Community Manager
  • 617 comments
  • January 19, 2023

Sorry to hear that, @dips ! :( Hope you are well! 


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • January 20, 2023

Thanks everyone! Getting there :)

Hope you all have a good weekend!


Nico Losschaert
Forum|alt.badge.img+12
  • On the path to Greatness
  • 681 comments
  • January 22, 2023

Thx for sharing @dips and good luck with your unfortunate news...🤞


Comment