Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12279

Опубликовано: 18 сент. 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

Отчет

Even if the code in the versions of libgit2 as shipped with Red Hat Enterprise Linux 7, and 8 are affected by this flaw, Red Hat does not support the NTFS filesystem nor Windows Subsystem for Linux (WSL). For this reason, the flaw has a Low Impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libgit2Fix deferred
Red Hat Enterprise Linux 8libgit2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1829407libgit2: NTFS protections inactive when running Git in the Windows Subsystem for Linux

EPSS

Процентиль: 90%
0.05577
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

CVSS3: 9.8
nvd
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

CVSS3: 9.8
debian
почти 6 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99. ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонента checkout.c реализации методов Git на языке C Libgit2, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05577
Низкий

8.1 High

CVSS3