cbcvebase.
CVE-2020-12278
published 2020-04-27

CVE-2020-12278: An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.11%
91.5th percentile
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibgit2< libgit2 0.28.4+dfsg.1-2 (bookworm)libgit2 0.28.4+dfsg.1-2 (bookworm)
libgit2libgit2< 0.28.40.28.4
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-2ubuntu0.10.28.4+dfsg.1-2ubuntu0.1
libgit2libgit2>= 0 < 1.1.0+dfsg.1-4.1ubuntu0.11.1.0+dfsg.1-4.1ubuntu0.1
libgit2libgit2>= 0 < 0.24.1-2ubuntu0.2+esm20.24.1-2ubuntu0.2+esm2
libgit2libgit2>= 0 < 0.26.0+dfsg.1-1.1ubuntu0.2+esm10.26.0+dfsg.1-1.1ubuntu0.2+esm1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.