TortoiseSVNÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-15

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14422£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


TortoiseSVN Version <= 1.12.1


Îó²î¸ÅÊö


TortoiseSVNÊÇSubversion°æ±¾¿ØÖÆÏµÍ³µÄÒ»¸öÃâ·Ñ¿ªÔ´¿Í»§¶Ë£¬¿ÉÒÔÓâԽʱ¼äµÄÖÎÀíÎļþºÍĿ¼  ¡£


¸ÃÎó²îÔ´ÓÚTortoiseSVNµÄURI´¦Öóͷ£³ÌÐò(Tsvncmd)ÔÊÐíÔÚExcelÊÂÇé²¾ÉϾÙÐж¨ÖƵÄdiff²Ù×÷£¬¸Ã²Ù×÷¿ÉÄܱ»ÓÃÓÚÔÚ²»ÊܺêÇå¾²ÉèÖñ £»¤µÄÇéÐÎÏ·­¿ªÔ¶³ÌÊÂÇé²¾£¬´Ó¶øÔì³Éí§Òâ´úÂëÖ´ÐÐ  ¡£¹¥»÷Õß¿ÉÄÜͨ¹ýÔÚÍøÂçÇý¶¯Æ÷ÖзÅÈëºê²¡¶¾À´Ê¹ÓÃÕâÒ»µã£¬ÆÈʹÊܺ¦Õß·­¿ªÊÂÇé²¾²¢Ö´ÐÐÆäÖеĺ겡¶¾  ¡£¸ÃÎó²î¿ÉÒÔͨ¹ýÓÃwebä¯ÀÀÆ÷»á¼ûÒ»¸öÌØÊâÉè¼ÆµÄURLÀ´´¥·¢  ¡£


Îó²îÑéÖ¤


EXP: https://cxsecurity.com/issue/WLB-2019080055  ¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬¹Ù·½ÒÑÐû²¼ÁËÐÞ¸´¸ÃÎó²îµÄ×îаæ v1.12.2£¬½¨Ò龡¿ìÏÂÔØÉý¼¶  ¡£¹Ù·½ÏÂÔØÁ´½Ó£º


https://tortoisesvn.net/downloads.zh.html  ¡£


²Î¿¼Á´½Ó


https://seclists.org/fulldisclosure/2019/Aug/7