CVE-2012-4465
published 2012-10-10CVE-2012-4465: Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service…
PriorityP433medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
3.38%
87.4th percentile
Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cgit | — | — |
| lars_hjemli | cgit | <= 0.9.0.3 | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
| lars_hjemli | cgit | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79m9-fj96-r8q8: Heap-based buffer overflow in the substr function in parsing
ghsa_unreviewed·2022-05-17
CVE-2012-4465 [MEDIUM] CWE-119 GHSA-79m9-fj96-r8q8: Heap-based buffer overflow in the substr function in parsing
Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.
Debian
CVE-2012-4465: cgit - Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 a...
vendor_debian·2012·CVSS 6.5
CVE-2012-4465 [MEDIUM] CVE-2012-4465: cgit - Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 a...
Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://git.zx2c4.com/cgit/commit/?id=7757d1b046ecb67b830151d20715c658867df1echttp://hjemli.net/pipermail/cgit/2012-July/000652.htmlhttp://secunia.com/advisories/50734http://www.openwall.com/lists/oss-security/2012/09/30/1http://www.openwall.com/lists/oss-security/2012/10/03/7http://www.securityfocus.com/bid/55724https://bugzilla.redhat.com/show_bug.cgi?id=820733http://git.zx2c4.com/cgit/commit/?id=7757d1b046ecb67b830151d20715c658867df1echttp://hjemli.net/pipermail/cgit/2012-July/000652.htmlhttp://secunia.com/advisories/50734http://www.openwall.com/lists/oss-security/2012/09/30/1http://www.openwall.com/lists/oss-security/2012/10/03/7http://www.securityfocus.com/bid/55724https://bugzilla.redhat.com/show_bug.cgi?id=820733
2012-10-10
Published