An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
{ "ubuntu_priority": "medium", "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libgit2-24", "binary_version": "0.24.1-2ubuntu0.2+esm2" }, { "binary_name": "libgit2-24-dbgsym", "binary_version": "0.24.1-2ubuntu0.2+esm2" }, { "binary_name": "libgit2-dev", "binary_version": "0.24.1-2ubuntu0.2+esm2" } ] }
{ "ubuntu_priority": "medium", "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libgit2-26", "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1" }, { "binary_name": "libgit2-26-dbgsym", "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1" }, { "binary_name": "libgit2-dev", "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1" } ] }
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "libgit2-28", "binary_version": "0.28.4+dfsg.1-2" }, { "binary_name": "libgit2-28-dbgsym", "binary_version": "0.28.4+dfsg.1-2" }, { "binary_name": "libgit2-dev", "binary_version": "0.28.4+dfsg.1-2" } ] }
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "libgit2-1.1", "binary_version": "1.1.0+dfsg.1-4.1build1" }, { "binary_name": "libgit2-1.1-dbgsym", "binary_version": "1.1.0+dfsg.1-4.1build1" }, { "binary_name": "libgit2-dev", "binary_version": "1.1.0+dfsg.1-4.1build1" }, { "binary_name": "libgit2-fixtures", "binary_version": "1.1.0+dfsg.1-4.1build1" } ] }