CVE-2016-10129
Severity
7.5HIGH
EPSS
4.8%
top 10.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 17
Description
The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2016-10129: cargo - The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1...↗2016
💬Community
2Bugzilla▶
CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2017-5338 CVE-2017-5339 libgit2: Two vulnerabilities fixed in libgit 0.25.1 and 0.24.6 [epel-all]↗2017-01-10
Bugzilla▶
CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2017-5338 CVE-2017-5339 libgit2: Two vulnerabilities fixed in libgit 0.25.1 and 0.24.6 [fedora-all]↗2017-01-10