5.9
CVSSv3

CVE-2016-10130

Published: 24/03/2017 Updated: 28/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The http_connect function in transports/http.c in libgit2 prior to 0.24.6 and 0.25.x prior to 0.25.1 might allow man-in-the-middle malicious users to spoof servers by leveraging clobbering of the error variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libgit2 project libgit2

libgit2 project libgit2 0.25.0

Vendor Advisories

Debian Bug report logs - #851406 libgit2: CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 Package: src:libgit2; Maintainer for src:libgit2 is Russell Sim <russellsim@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Jan 2017 15:54:05 UTC Severity: important Tags: confirmed, jessie, patch, ...
An issue has been discovered when checking certificate validity before clobbering the error variable A valid parameter is provided to indicate whether the native cryptographic library considered the certificate to be correct This parameter is always 1/true before the fix leading to a possible man-in-the-middle (MITM) ...