PT-2018-3955 · Libgit2+2 · Libgit2+2

Riccardo Schirone

·

Published

2018-07-09

·

Updated

2024-06-15

·

CVE-2018-10887

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions libgit2 versions prior to 0.27.3
Description The issue is related to the git delta apply function in the delta.c component of libgit2, which is used for Git implementation in C. It involves an out of bound read due to an unexpected sign extension, potentially leading to an integer overflow. This could allow a remote attacker to access confidential data or cause a Denial of Service, possibly leaking memory addresses.
Recommendations For versions prior to 0.27.3, update to version 0.27.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the git delta apply function until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1992
ALT-PU-2018-2706
BDU:2023-07783
CVE-2018-10887
DLA-1477-1
DLA-2936-1
OPENSUSE-SU-2018_2502-1
OPENSUSE-SU-2018_3519-1
OPENSUSE-SU-2024:10943-1
SUSE-SU-2018:2469-1
SUSE-SU-2018:3440-1

Affected Products

Alt Linux
Suse
Libgit2