CVE-2016-10129

Severity
7.5HIGH
EPSS
4.8%
top 10.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 17

Description

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianlibgit2< 0.25.1+really0.24.6-1+3
Debiancargo< 0.17.0-1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7gh2-q8m8-26r9: The Git Smart Protocol support in libgit2 before 02022-05-17
CVEList
CVE-2016-10129: The Git Smart Protocol support in libgit2 before 02017-03-24
OSV
CVE-2016-10129: The Git Smart Protocol support in libgit2 before 02017-03-24

📋Vendor Advisories

1
Debian
CVE-2016-10129: cargo - The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1...2016

💬Community

2
Bugzilla
CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2017-5338 CVE-2017-5339 libgit2: Two vulnerabilities fixed in libgit 0.25.1 and 0.24.6 [epel-all]2017-01-10
Bugzilla
CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2017-5338 CVE-2017-5339 libgit2: Two vulnerabilities fixed in libgit 0.25.1 and 0.24.6 [fedora-all]2017-01-10
CVE-2016-10129 (HIGH CVSS 7.5) | The Git Smart Protocol support in l | cvebase.io