CVE-2020-12278: Critical severity centos libgcc vulnerability
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12278?
The severity of CVE-2020-12278 is critical, with a CVSS score of 9.8.
What is the affected software for CVE-2020-12278?
The affected software for CVE-2020-12278 is Libgit2 (version up to exclusive 0.28.4) and Debian Linux (version exactly 9.0).
How does CVE-2020-12278 occur?
CVE-2020-12278 occurs due to mishandling of equivalent filenames that exist because of NTFS Alternate Data Streams in libgit2.
Can CVE-2020-12278 result in remote code execution?
Yes, CVE-2020-12278 may allow remote code execution when cloning a repository.
How can I fix CVE-2020-12278?
To fix CVE-2020-12278, it is recommended to update to a version of libgit2 that is greater than or equal to 0.28.4 or apply the necessary patches.