ZeroHour

CVE-2020-12278

CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

Vendors
libgit2debian
Products
libgit2, debian linux
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.