GitHub¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-10-08

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17456 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


GitHub Desktop 1.4.1¼°¸üÔç°æ±¾

AtomÔ̺¬ÁËÒ»ÑùµÄǶÈëʽGit £¬Ò²Êܵ½ÁËÓ°Ïì¡£°æ±¾1.31.2ºÍ1.32.0-beta3


·ì϶¸ÅÊö


10ÔÂ5ÈÕ £¬GitÏîÄ¿Åû¶ÁËÒ»¸ö·ì϶ £¬±àºÅΪCVE-2018-17456¡£µ±Óû§¿Ë¡¶ñÒâ´æ´¢¿âʱ £¬¸Ã·ì϶¿ÉÄܻᵼÖÂÖ´ÐÐËÁÒâ´úÂë¡£


ÈôÊÇÖ´ÐÐÁËÌØ¶¨µÄºÅÁî £¬¼´¡°git clone --recurse-submodules¡± £¬ÆäÈí¼þÖеķì϶ÔÊÐíÔÚ¿Í»§¶Ëƽ̨ÉÏÖ´ÐÐËÁÒâ´úÂ롣ĿǰֻÓÐUnixƽ̨Êܵ½ÁËÓ°Ïì¡£


΢Èí³ÎÇåÁËÕâ¸öÎÊÌâ½ö½öÓ°Ïì»ùÓÚUnixµÄƽ̨ £¬ÈçLinuxºÍmacOS £¬»òºÏÓÃÓÚÔÚWindows×ÓϵͳLinux£¨WSL£©µÄLinux¿¯ÐаæÖÐÔËÐÐgitµÄÈË¡£ÕâÊÇÓÉÓÚÔÚÀûÓ÷ì϶ʱдÈë´ÅÅ̵ÄÎļþÃû³ÆÖбØÒªÃ°ºÅ £¬²¢ÇÒÓÉÓÚWindowsÎļþϵͳ²»Ö§³ÖðºÅ £¬Òò¶øGit for Windows²»»áдÈë¸ÃÎļþ¡£


GitHub.comºÍGitHub Enterprise¶¼²»»áÖ±½ÓÊÜ´Ë·ì϶ӰÏì¡£µ«ÊÇ £¬ÓëÏÈǰ·¢Ïֵķì϶һÑù £¬GitHub.com½«¼ì²â¶ñÒâ´æ´¢¿â £¬²¢»Ø¾ø³¢ÊÔ´´½¨ËüÃǵÄÍÆËÍ»òAPIÒªÇó¡£ÓµÓд˼ì²âÖ°ÄܵÄGitHub Enterprise½«ÓÚ10ÔÂ9ÈÕ°ä²¼¡£


·ì϶ÑéÖ¤


´Ë·ì϶ÓëCVE-2017-1000117¼«¶ÈÀàËÆ £¬ÓÉÓÚËüÃǶ¼ÊÇÓë×ÓÄ£¿éÓйصÄÑ¡Ïî×¢Èë¹¥»÷¡£ÔÚ֮ǰµÄ¹¥»÷ÖÐ £¬¶ñÒâ´æ´¢¿â»á½«Ò»¸ö.gitmodulesÎļþ·¢Ë͵½Ò»¸öÔ¶³Ì´æ´¢¿â £¬ÆäÖÐÒ»¸ö×ÓÄ£¿éÒÔ¶Ì»®Ïß¡°-¡±¿ªÍ·¡£ÓÉGit²úÉúµÄssh·¨Ê½½«°ÑËüÚ¹ÊÍΪһ¸öÑ¡Ïî¡£³ýÁËÑ¡Ïî×¢ÈëÕë¶Ô×Ógit£¨child git£©¿Ë¡Ëü×Ô¼º±í £¬´Ë¹¥»÷ÒÔÀàËÆµÄ·½Ê½½øÐС£


¶ñÒâ¡°.gitmodules¡±ÑùÀý £¬ÔËÐÓ×°git clone --recurse-submodules¡±Ê± £¬Git»á½âÎöÌṩµÄ.gitmodulesÎļþÖеÄURL×Ö¶Î £¬²¢½«Æä×÷Ϊ²ÎÊýäĿµØ´«µÝ¸ø¡°git clone¡±×Ó¹ý³Ì¡£ÈôÊÇURL×Ö¶ÎÉèÖÃΪÒÔ¶Ì»®Ïß¿ªÍ·µÄ×Ö·û´® £¬Ôò´Ë¡°git clone¡±×Ó¹ý³Ì½«URLÚ¹ÊÍΪѡÏî¡£Õâ¿ÉÄܵ¼ÖÂÖ´Ð㬵ÈÏîÄ¿ÖеÄËÁÒâ¾ç±¾×÷ΪÔËÐÓ×°git clone¡±µÄÓû§¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


GitHub¼¤ÀøËùÓÐGitHub×ÀÃæÓû§¸üе½×ÀÃæÀûÓ÷¨Ê½ÖÐÏÖÓеÄ×îа汾£¨1.4.2ºÍ1.4.3-beta0£©
Atomͨ¹ýʵÏÖÒÔÏÂÈκÎÒ»Ïî £¬È·±£Ê¹ÓõÄÊÇ×îÐÂAtom°æ±¾£º
Windows£º´Ó¹¤¾ßÀ¸ÖÐ £¬µ¥»÷¡°Ô®ÊÖ¡± - >¡°²é³­¸üС± 
MacOS£º´Ó²Ëµ¥À¸Öе¥»÷¡°Atom¡± - >¡°²é³­¸üС±
Linux£ºÍ¨¹ý´Óatom.ioÏÂÔØ×îа汾ÊÖ¶¯¸üÐÂ


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/git-project-patches-remote-code-execution-vulnerability-in-git/
https://seclists.org/oss-sec/2018/q4/19