CVE-2020-12278
Summary
| CVE | CVE-2020-12278 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-27 17:15:00 UTC |
| Updated | 2023-02-24 00:15:00 UTC |
| Description | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352. |
Risk And Classification
Problem Types: CWE-706
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Disallow NTFS Alternate Data Stream attacks, even on Linux/macOS · libgit2/libgit2@3f7851e · GitHub | MISC | github.com | Patch |
| Release libgit2 v0.28.4 · libgit2/libgit2 · GitHub | MISC | github.com | Release Notes |
| path: also guard `.gitmodules` against NTFS Alternate Data Streams · libgit2/libgit2@e1832eb · GitHub | MISC | github.com | Patch |
| Release libgit2 v0.99.0 · libgit2/libgit2 · GitHub | MISC | github.com | Release Notes |
| [SECURITY] [DLA 2936-1] libgit2 security update | MLIST | lists.debian.org | |
| Git mishandles the default NTFS Alternate Data Streams · Advisory · git/git · GitHub | MISC | github.com | Third Party Advisory |
| [SECURITY] [DLA 3340-1] libgit2 security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.