6.5
CVSSv3

CVE-2018-10888

Published: 10/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may use this flaw to cause a Denial of Service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libgit2 libgit2

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #903508 libgit2: CVE-2018-10888: an improper input validation leads to an out-of-bound read in git_delta_apply, allowing to read beyond delta limits Package: src:libgit2; Maintainer for src:libgit2 is Russell Sim <russellsim@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Da ...