383
VMScore

CVE-2016-8568

Published: 03/02/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The git_commit_message function in oid.c in libgit2 prior to 0.24.3 allows remote malicious users to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 25

fedoraproject fedora 24

fedoraproject fedora 23

suse linux enterprise 12.0

opensuse leap 42.2

opensuse leap 42.1

opensuse opensuse 13.2

libgit2 project libgit2

Vendor Advisories

Debian Bug report logs - #840227 libgit2: CVE-2016-8568 CVE-2016-8569 Package: src:libgit2; Maintainer for src:libgit2 is Russell Sim <russellsim@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Oct 2016 18:03:02 UTC Severity: grave Tags: confirmed, jessie, security, upstream Found in ...
A heap-based read out-of-bounds access has been discovered while parsing a malformed object file ...