cbcvebase.
CVE-2020-12279
published 2020-04-27

CVE-2020-12279: An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names…

PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.09%
91.4th percentile
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibgit2< libgit2 0.28.4+dfsg.1-2 (bookworm)libgit2 0.28.4+dfsg.1-2 (bookworm)
libgit2libgit2< 0.28.40.28.4
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-20.28.4+dfsg.1-2
libgit2libgit2>= 0 < 0.28.4+dfsg.1-2ubuntu0.10.28.4+dfsg.1-2ubuntu0.1
libgit2libgit2>= 0 < 1.1.0+dfsg.1-4.1ubuntu0.11.1.0+dfsg.1-4.1ubuntu0.1
libgit2libgit2>= 0 < 0.24.1-2ubuntu0.2+esm20.24.1-2ubuntu0.2+esm2
libgit2libgit2>= 0 < 0.26.0+dfsg.1-1.1ubuntu0.2+esm10.26.0+dfsg.1-1.1ubuntu0.2+esm1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.