An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libgit2 | Mar 22, 2022 | Apr 27, 2020 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-libgit2 | Aug 31, 2020 | Apr 27, 2020 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 27, 2020 | |
| Ubuntu | ubuntu-pro-upgrade-libgit2-24ubuntu-pro-upgrade-libgit2-26ubuntu-upgrade-libgit2-1-1ubuntu-upgrade-libgit2-1-5ubuntu-upgrade-libgit2-28 | Mar 6, 2024 | Apr 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub