PT-2015-4907 · Dulwich · Dulwich
Ivan Fratric
·
Published
2015-03-28
·
Updated
2024-07-12
·
CVE-2015-0838
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dulwich versions prior to 0.9.9
Description
The issue is related to a buffer overflow in the C implementation of the
apply delta function in pack.c. This allows remote attackers to execute arbitrary code via a crafted pack file.Recommendations
For versions prior to 0.9.9, update to version 0.9.9 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted pack files until the update is applied.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dulwich