| Name | CVE-2019-1354 |
| Description | A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387. |
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| git (PTS) | bullseye | 1:2.30.2-1+deb11u2 | fixed |
| bullseye (security) | 1:2.30.2-1+deb11u4 | fixed | |
| bookworm, bookworm (security) | 1:2.39.5-0+deb12u2 | fixed | |
| trixie | 1:2.47.3-0+deb13u1 | fixed | |
| forky, sid | 1:2.51.0-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| git | source | buster | 1:2.20.1-2+deb10u1 | |||
| git | source | (unstable) | 1:2.24.0-2 | unimportant |
https://git.kernel.org/pub/scm/git/git.git/commit/?id=e1d911dd4c7b76a5a8cec0f5c8de15981e34da83
https://www.openwall.com/lists/oss-security/2019/12/13/1