CVE-2020-12278
published 2020-04-27CVE-2020-12278: An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.11%
91.5th percentile
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libgit2 | < libgit2 0.28.4+dfsg.1-2 (bookworm) | libgit2 0.28.4+dfsg.1-2 (bookworm) |
| libgit2 | libgit2 | < 0.28.4 | 0.28.4 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2 | 0.28.4+dfsg.1-2 |
| libgit2 | libgit2 | >= 0 < 0.28.4+dfsg.1-2ubuntu0.1 | 0.28.4+dfsg.1-2ubuntu0.1 |
| libgit2 | libgit2 | >= 0 < 1.1.0+dfsg.1-4.1ubuntu0.1 | 1.1.0+dfsg.1-4.1ubuntu0.1 |
| libgit2 | libgit2 | >= 0 < 0.24.1-2ubuntu0.2+esm2 | 0.24.1-2ubuntu0.2+esm2 |
| libgit2 | libgit2 | >= 0 < 0.26.0+dfsg.1-1.1ubuntu0.2+esm1 | 0.26.0+dfsg.1-1.1ubuntu0.2+esm1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libgit2 vulnerabilities
osv·2024-03-05·CVSS 9.8
CVE-2020-12278 [CRITICAL] libgit2 vulnerabilities
libgit2 vulnerabilities
It was discovered that libgit2 mishandled equivalent filenames on NTFS
partitions. If a user or automated system were tricked into cloning a
specially crafted repository, an attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2020-12278, CVE-2020-12279)
It was discovered that libgit2 did not perform certificate checking by
default. An attacker could possibly use this issue to perform a
machine-in-the-middle attack. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-22742)
It was discovered that libgit2 could be made to run into an infinite loop.
An attacker could possibly use this issue to cause a denial of service.
This i
GHSA
GHSA-w32v-c4gg-xc8p: An issue was discovered in libgit2 before 0
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-12278 [HIGH] CWE-20 GHSA-w32v-c4gg-xc8p: An issue was discovered in libgit2 before 0
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
OSV
CVE-2020-12278: An issue was discovered in libgit2 before 0
osv·2020-04-27·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278: An issue was discovered in libgit2 before 0
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Ubuntu
libgit2 vulnerabilities
vendor_ubuntu·2024-03-05·CVSS 9.8
CVE-2024-24575 [CRITICAL] libgit2 vulnerabilities
Title: libgit2 vulnerabilities
Summary: Several security issues were fixed in libgit2.
It was discovered that libgit2 mishandled equivalent filenames on NTFS
partitions. If a user or automated system were tricked into cloning a
specially crafted repository, an attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2020-12278, CVE-2020-12279)
It was discovered that libgit2 did not perform certificate checking by
default. An attacker could possibly use this issue to perform a
machine-in-the-middle attack. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-22742)
It was discovered that libgit2 could be made to run into an infinite loop.
An attacker co
Debian
CVE-2020-12278: libgit2 - An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c ...
vendor_debian·2020·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278: libgit2 - An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c ...
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Scope: local
bookworm: resolved (fixed in 0.28.4+dfsg.1-2)
bullseye: resolved (fixed in 0.28.4+dfsg.1-2)
forky: resolved (fixed in 0.28.4+dfsg.1-2)
sid: resolved (fixed in 0.28.4+dfsg.1-2)
trixie: resolved (fixed in 0.28.4+dfsg.1-2)
Red Hat
libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
vendor_redhat·2019-09-18·CVSS 8.8
CVE-2020-12278 [HIGH] CWE-73 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Statement: Even if the code in the versions of libgit2 as shipped with Red Hat Enterprise Linux 7, and 8 are affected by this flaw, Red Hat does not support the NTFS filesystem. For this reason, the flaw has a Low Impact.
Package: libgit2 (Red Hat Enterprise Linux 7) - Fix deferred
Package: libgit2 (Red Hat Enterprise Linux 8) - Fix deferred
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-12278 [CRITICAL] CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2020-12278 libgit2:0.28/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-12278 [CRITICAL] CVE-2020-12278 libgit2:0.28/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
CVE-2020-12278 libgit2:0.28/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2020-12278 libgit2:0.27/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-12278 [CRITICAL] CVE-2020-12278 libgit2:0.27/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
CVE-2020-12278 libgit2:0.27/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [epel-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-12278 [CRITICAL] CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [epel-all]
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2020-12278 libgit2:0.26/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
bugzilla·2020-04-29·CVSS 9.8
CVE-2020-12278 [CRITICAL] CVE-2020-12278 libgit2:0.26/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
CVE-2020-12278 libgit2:0.26/libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
bugzilla·2020-04-29·CVSS 8.8
CVE-2020-12278 [HIGH] CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
CVE-2020-12278 libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams
An issue was discovered in libgit2 where path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is the libgit2 variant of CVE-2019-1352.
References:
https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj
https://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01
https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cb
https://github.com/libgit2/libgit2/releases/tag/v0.28.4
https://github.com/libgit2/libgit2/releases/tag/v0.99.0
Discussion:
Statement:
Even if the code in the versions of libgit2 as
https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vjhttps://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cbhttps://github.com/libgit2/libgit2/releases/tag/v0.28.4https://github.com/libgit2/libgit2/releases/tag/v0.99.0https://lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlhttps://lists.debian.org/debian-lts-announce/2023/02/msg00034.htmlhttps://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vjhttps://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cbhttps://github.com/libgit2/libgit2/releases/tag/v0.28.4https://github.com/libgit2/libgit2/releases/tag/v0.99.0https://lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlhttps://lists.debian.org/debian-lts-announce/2023/02/msg00034.html
2020-04-27
Published