Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12278

Опубликовано: 18 сент. 2019
Источник: redhat
CVSS3: 8.1

Описание

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

Отчет

Even if the code in the versions of libgit2 as shipped with Red Hat Enterprise Linux 7, and 8 are affected by this flaw, Red Hat does not support the NTFS filesystem. For this reason, the flaw has a Low Impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libgit2Fix deferred
Red Hat Enterprise Linux 8libgit2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=1829397libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

CVSS3: 9.8
nvd
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

CVSS3: 9.8
debian
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99. ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонента path.c реализации методов Git на языке C Libgit2, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

8.1 High

CVSS3