{ "document": { "aggregate_severity": { "text": "critical" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "description", "text": "An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.", "title": "Vulnerability Description" } ], "publisher": { "category": "other", "contact_details": "gdt@cpan.org", "name": "giterlizzi", "namespace": "https://github.com/giterlizzi/" }, "references": [ { "category": "self", "summary": "CPANSA-Git-Raw-2020-12278-libgit2 JSON", "url": "https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2020/cpansa-git-raw-2020-12278-libgit2.json" }, { "category": "external", "summary": "https://github.com/libgit2/libgit2/releases/tag/v0.28.4", "url": "https://github.com/libgit2/libgit2/releases/tag/v0.28.4" }, { "category": "external", "summary": "https://github.com/libgit2/libgit2/releases/tag/v0.99.0", "url": "https://github.com/libgit2/libgit2/releases/tag/v0.99.0" }, { "category": "external", "summary": "https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cb", "url": "https://github.com/libgit2/libgit2/commit/e1832eb20a7089f6383cfce474f213157f5300cb" }, { "category": "external", "summary": "https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj", "url": "https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj" }, { "category": "external", "summary": "https://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01", "url": "https://github.com/libgit2/libgit2/commit/3f7851eadca36a99627ad78cbe56a40d3776ed01" }, { "category": "external", "summary": "https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html", "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html" }, { "category": "external", "summary": "CVE-2020-12278 (NVD)", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12278" } ], "title": "Git-Raw vulnerability", "tracking": { "current_release_date": "2020-04-27T00:00:00", "generator": { "engine": { "name": "CSAF Perl Toolkit", "version": "0.26" } }, "id": "CPANSA-Git-Raw-2020-12278-libgit2", "initial_release_date": "2020-04-27T00:00:00", "revision_history": [ { "date": "2020-04-27T00:00:00", "number": "1", "summary": "First release" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "category": "product_version_range", "name": "vers:cpan/>=0.83|<=0.84", "product": { "name": "Git-Raw greater than or equal 0.83 and less than or equal 0.84", "product_id": "CSAFPID-0001", "product_identification_helper": { "purl": "pkg:cpan/Git-Raw" } } } ], "category": "product_name", "name": "Git-Raw" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-12278", "cwe": { "id": "CWE-706", "name": "Use of Incorrectly-Resolved Name or Reference" }, "notes": [ { "category": "description", "text": "An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.", "title": "Vulnerability Description" } ], "product_status": { "known_affected": [ "CSAFPID-0001" ] }, "scores": [ { "cvss_v2": { "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0" }, "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ] } ] }