PT-2018-10416 · Git+3 · Git+3

Published

2018-05-30

·

Updated

2024-06-15

·

CVE-2018-11233

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Git versions prior to 2.13.7 Git versions 2.14.x prior to 2.14.4 Git versions 2.15.x prior to 2.15.2 Git versions 2.16.x prior to 2.16.4 Git versions 2.17.x prior to 2.17.1
Description The issue arises from code intended to sanity-check pathnames on NTFS, which can lead to reading out-of-bounds memory.
Recommendations For Git versions prior to 2.13.7, update to version 2.13.7 or later. For Git versions 2.14.x prior to 2.14.4, update to version 2.14.4 or later. For Git versions 2.15.x prior to 2.15.2, update to version 2.15.2 or later. For Git versions 2.16.x prior to 2.16.4, update to version 2.16.4 or later. For Git versions 2.17.x prior to 2.17.1, update to version 2.17.1 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2090
CVE-2018-11233
MGASA-2018-0267
OPENSUSE-SU-2018_1553-1
OPENSUSE-SU-2020:0598-1
OPENSUSE-SU-2020_0598-1
OPENSUSE-SU-2024:10786-1
RHSA-2018:2147
SUSE-SU-2018:1566-1
SUSE-SU-2018:1566-2
SUSE-SU-2018:1872-1
SUSE-SU-2020:1121-1
USN-3671-1

Affected Products

Alt Linux
Git
Suse
Ubuntu