News: 1649854806

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Git for Windows issues update to fix running-someone-else’s-code vuln

(2022/04/13)


After a hefty [1]Patch Tuesday comes [2]news of an update for Git to deal with a vulnerability for the source shack when run on Microsoft's Windows.

A variety of releases were emitted by the team. These include the latest maintenance release, 2.35.2, along with updates for older maintenance tracks (v2.30.3, v2.31.2, v2.32.1, v2.33.2, and v2.34.2.)

The update is solely concerned with [3]CVE-2022-24765 , an interesting bug which afflicts the Git for Windows fork of Git. The vulnerability affects multi-user hardware where untrusted parties have write access to the same hard disk.

[4]

Arguably, if an "untrusted party" has write access to a hard disk, then all bets are off when it comes to the nooks and crannies of a PC anyway.

[5]

[6]

In this case, the miscreants would only need to create the folder c:\.git , "which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory," according to NIST.

The result is that Git would use the config in the directory.

[7]

NIST went on to list potentially vulnerable products, which included Visual Studio. "Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash."

[8]Windows is now built on Git, but Microsoft has found some bottlenecks

[9]Open-source Kubernetes tool Argo CD has a high-severity path traversal flaw: Patch now

[10]Git security vulnerability could lead to an attack of the (repo) clones

[11]Complaints mount after GitHub launches new algorithmic feed

The Git team was little blunter about the vulnerability, and warned that "Merely having a Git-aware prompt that runs 'git status' (or 'git diff') and navigating to a directory which is supposedly not a Git worktree, or opening such a directory in an editor or IDE such as VS Code or Atom, will potentially run commands defined by that other user."

Not nice, but also very specific in terms of affected systems. These need to be multi-user machines, likely running Windows (probably due to how the file system of the OS works.) Ultimately, it is an arbitrary code issue, if one that requires access to the disk to implement.

To deal with the issue, the Git team recommends an update. Alternatively, a user could create that .git folder themselves and remove read/write access as workaround or "define or extend 'GIT_CEILING_DIRECTORIES' to cover the parent directory of the user profile," according to NIST.

The code shack gave a hattip to 俞晨东 for finding the bug and Johannes Schindelin for working on a fix.

[12]

Ultimately, if you can, then patching seems the best way to go. As the Git team noted: "Please update at your earliest opportunity." ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2022/04/13/microsoft_patch_tuesday/

[2] https://lore.kernel.org/lkml/20220412180510.GA2173@szeder.dev/T/#t

[3] https://nvd.nist.gov/vuln/detail/CVE-2022-24765

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ylbzsg@0Sby5YT3JxtqPUQAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ylbzsg@0Sby5YT3JxtqPUQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ylbzsg@0Sby5YT3JxtqPUQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ylbzsg@0Sby5YT3JxtqPUQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2017/05/25/windows_is_now_built_on_git/

[9] https://www.theregister.com/2022/02/04/argo_cd_0day_kubernetes/

[10] https://www.theregister.com/2018/05/30/git_vulnerability_could_lead_to_an_attack_of_the_repo_clones/

[11] https://www.theregister.com/2022/03/23/github_for_you/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ylbzsg@0Sby5YT3JxtqPUQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Hit them biscuits with another touch of gravy,
Burn that sausage just a match or two more done.
Pour my black old coffee longer,
While that smell is gettin' stronger
A semi-meal ain't nuthin' much to want.

Loan me ten, I got a feelin' it'll save me,
With an ornery soul who don't shoot pool for fun,
If that coat'll fit you're wearin',
The Lord'll bless your sharin'
A semi-friend ain't nuthin' much to want.

And let me halfway fall in love,
For part of a lonely night,
With a semi-pretty woman in my arms.
Yes, I could halfway fall in deep--
Into a snugglin', lovin' heap,
With a semi-pretty woman in my arms.
-- Elroy Blunt