PT-2018-3955 · Libgit2+2 · Libgit2+2

Riccardo Schirone

·

Publicado

2018-07-09

·

Atualizado

2024-06-15

·

CVE-2018-10887

CVSS v2.0

9.4

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions libgit2 versions prior to 0.27.3
Description The issue is related to the git delta apply function in the delta.c component of libgit2, which is used for Git implementation in C. It involves an out of bound read due to an unexpected sign extension, potentially leading to an integer overflow. This could allow a remote attacker to access confidential data or cause a Denial of Service, possibly leaking memory addresses.
Recommendations For versions prior to 0.27.3, update to version 0.27.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the git delta apply function until a patch is available.

Exploit

Correção

DoS

Out of bounds Read

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1992
ALT-PU-2018-2706
BDU:2023-07783
CVE-2018-10887
DLA-1477-1
DLA-2936-1
OPENSUSE-SU-2018_2502-1
OPENSUSE-SU-2018_3519-1
OPENSUSE-SU-2024:10943-1
SUSE-SU-2018:2469-1
SUSE-SU-2018:3440-1

Produtos afetados

Alt Linux
Suse
Libgit2