Related Vulnerabilities: CVE-2019-1348  

The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

Severity High

Remote Yes

Type Arbitrary file overwrite

Description

The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

AVG-1073 git 2.24.0-1 2.24.1-1 High Testing

https://github.com/git/git/commit/68061e3470210703cb15594194718d35094afdc0
https://lkml.org/lkml/2019/12/10/905