漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Git for Windows' installer can be tricked into executing an untrusted binary
Vulnerability Description
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C:\mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C:\`.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Git for Windows 代码问题漏洞
Vulnerability Description
Git for Windows是Git groups的用于 Windows 的 Git。 Git for Windows v2.37.1之前版本存在代码问题漏洞,该漏洞源于安装程序可能会被欺骗执行不受信任的二进制文件。
CVSS Information
N/A
Vulnerability Type
N/A