-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
excluded: LEGACY_FALSE_POSITIVE(DO NOT USE) Vulnerability marked as false positive before we introduced the triage process(DO NOT USE) Vulnerability marked as false positive before we introduced the triage process
Description
CVE-2020-12279 references github.com/git/git, which may be a Go module.
Description:
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
References:
- NIST: https://nvd.nist.gov/vuln/detail/CVE-2020-12279
- web: https://github.com/libgit2/libgit2/releases/tag/v0.99.0
- web: https://github.com/libgit2/libgit2/releases/tag/v0.28.4
- advisory: GHSA-589j-mmg9-733v
- fix: libgit2/libgit2@64c612c
- web: https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html
- web: https://lists.debian.org/debian-lts-announce/2023/02/msg00034.html
- Imported by: https://pkg.go.dev/github.com/git/git?tab=importedby
Cross references:
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2022-29187 #513 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2022-39253 #1068 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2022-39260 #1069 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2022-23521 #1499 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2022-41903 #1500 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2023-22490 #1562 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2023-23946 #1563 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2023-25652 #1739 NOT_GO_CODE
- Module github.com/git/git appears in issue x/vulndb: potential Go vuln in github.com/git/git: CVE-2023-29007 #1741 NOT_GO_CODE
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/git/git
vulnerable_at: 2.42.1+incompatible
packages:
- package: n/a
cves:
- CVE-2020-12279
references:
- web: https://github.com/libgit2/libgit2/releases/tag/v0.99.0
- web: https://github.com/libgit2/libgit2/releases/tag/v0.28.4
- advisory: https://github.com/git/git/security/advisories/GHSA-589j-mmg9-733v
- fix: https://github.com/libgit2/libgit2/commit/64c612cc3e25eff5fb02c59ef5a66ba7a14751e4
- web: https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html
- web: https://lists.debian.org/debian-lts-announce/2023/02/msg00034.html
Metadata
Metadata
Assignees
Labels
excluded: LEGACY_FALSE_POSITIVE(DO NOT USE) Vulnerability marked as false positive before we introduced the triage process(DO NOT USE) Vulnerability marked as false positive before we introduced the triage process