An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.24.1-2ubuntu0.2+esm2", "binary_name": "libgit2-24" }, { "binary_version": "0.24.1-2ubuntu0.2+esm2", "binary_name": "libgit2-24-dbgsym" }, { "binary_version": "0.24.1-2ubuntu0.2+esm2", "binary_name": "libgit2-dev" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1", "binary_name": "libgit2-26" }, { "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1", "binary_name": "libgit2-26-dbgsym" }, { "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm1", "binary_name": "libgit2-dev" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.28.4+dfsg.1-2", "binary_name": "libgit2-28" }, { "binary_version": "0.28.4+dfsg.1-2", "binary_name": "libgit2-28-dbgsym" }, { "binary_version": "0.28.4+dfsg.1-2", "binary_name": "libgit2-dev" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.1.0+dfsg.1-4.1build1", "binary_name": "libgit2-1.1" }, { "binary_version": "1.1.0+dfsg.1-4.1build1", "binary_name": "libgit2-1.1-dbgsym" }, { "binary_version": "1.1.0+dfsg.1-4.1build1", "binary_name": "libgit2-dev" }, { "binary_version": "1.1.0+dfsg.1-4.1build1", "binary_name": "libgit2-fixtures" } ] }