TortoiseSVNÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-15

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14422£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


TortoiseSVN Version <= 1.12.1


·ì϶¸ÅÊö


TortoiseSVNÊÇSubversion°æ±¾½ÚÔìϵͳµÄÒ»¸öÃâ·Ñ¿ªÔ´¿Í»§¶Ë£¬Äܹ»³¬¹ý¹¦·òµÄÖÎÀíÎļþºÍĿ¼ ¡£


¸Ã·ì϶ԴÓÚTortoiseSVNµÄURI´¦Ö÷¨Ê½(Tsvncmd)ÔÊÐíÔÚExcel¹¤×÷²¾ÉϽøÐж¨ÔìµÄdiff²Ù×÷£¬¸Ã²Ù×÷¿ÉÄܱ»ÓÃÓÚÔÚ²»Êܺ갲ȫÉèÖñ£»¤µÄÇé¿öÏ´ò¿ªÔ¶³Ì¹¤×÷²¾£¬´Ó¶øÔì³ÉËÁÒâ´úÂëÖ´ÐÐ ¡£¹¥»÷Õß¿ÉÄÜͨ¹ýÔÚÍøÂçÇý¶¯Æ÷ÖзÅÈëºê²¡¶¾À´ÀûÓÃÕâÒ»µã£¬ÆÈʹÊܺ¦Õß´ò¿ª¹¤×÷²¾²¢Ö´ÐÐÆäÖеĺ겡¶¾ ¡£¸Ã·ì϶Äܹ»Í¨¹ýÓÃwebä¯ÀÀÆ÷½Ó¼ûÒ»¸ö³ö¸ñÉè¼ÆµÄURLÀ´´¥·¢ ¡£


·ì϶ÑéÖ¤


EXP: https://cxsecurity.com/issue/WLB-2019080055 ¡£


½¨¸´½¨Òé


Ŀǰ£¬¹Ù·½ÒѰ䲼Á˽¨¸´¸Ã·ì϶µÄ×îаæ v1.12.2£¬½¨Ò龡¿ìÏÂÔØÉý¼¶ ¡£¹Ù·½ÏÂÔØÁ´½Ó£º


https://tortoisesvn.net/downloads.zh.html ¡£


²Î¿¼Á´½Ó


https://seclists.org/fulldisclosure/2019/Aug/7