5
CVSSv2

CVE-2011-1027

Published: 20/03/2011 Updated: 22/12/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit prior to 0.8.3.5 allows remote malicious users to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

lars hjemli cgit 0.7.1

lars hjemli cgit 0.8.3.1

lars hjemli cgit 0.6.1

lars hjemli cgit 0.6

lars hjemli cgit 0.8

lars hjemli cgit 0.3

lars hjemli cgit 0.5

lars hjemli cgit 0.8.1.1

lars hjemli cgit 0.2

lars hjemli cgit 0.8.3.2

lars hjemli cgit 0.8.3

lars hjemli cgit 0.1

lars hjemli cgit 0.6.2

lars hjemli cgit 0.8.2.2

lars hjemli cgit 0.7.2

lars hjemli cgit 0.4

lars hjemli cgit 0.8.2

lars hjemli cgit 0.8.1

lars hjemli cgit 0.8.3.3

lars hjemli cgit

lars hjemli cgit 0.8.2.1

lars hjemli cgit 0.7

lars hjemli cgit 0.6.3

fedoraproject fedora 13

fedoraproject fedora 15

fedoraproject fedora 14