PT-2016-2695 · Git+4 · Git+4

Laël Cellier

·

Published

2016-03-16

·

Updated

2024-06-15

·

CVE-2016-2315

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions git versions prior to 2.7.4
Description The issue is related to the use of an incorrect integer data type in the revision.c file of the git distributed version control system. This can be exploited by remote attackers to execute arbitrary code via a long filename or many nested trees, leading to a heap-based buffer overflow.
Recommendations For git versions prior to 2.7.4, update to version 2.7.4 or later to resolve the issue.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-02087
CESA-2016_0496
CVE-2016-2315
DSA-3521-1
MGASA-2016-0119
OPENSUSE-SU-2016_0802-1
OPENSUSE-SU-2016_0803-1
OPENSUSE-SU-2016_0829-1
OPENSUSE-SU-2016_0832-1
OPENSUSE-SU-2024:10099-1
OPENSUSE-SU-2024:10137-1
RHSA-2016:0496
RHSA-2016:0497
RHSA-2016_0496
SUSE-SU-2016:0796-1
SUSE-SU-2016:0798-1
SUSE-SU-2016_0796-1
SUSE-SU-2016_0798-1
USN-2938-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Git