CVE-2016-8568

CWE-125Out-of-bounds Read9 documents7 sources
Severity
5.5MEDIUM
EPSS
0.5%
top 35.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateMay 14

Description

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianlibgit2< 0.24.5-1+3
Debiancargo< 0.17.0-1+1
NVDopensuse/leap42.1, 42.2+1

Also affects: Fedora 23, 24, 25, Linux Enterprise 12.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jxhv-8xc9-73hq: The git_commit_message function in oid2022-05-14
CVEList
CVE-2016-8568: The git_commit_message function in oid2017-02-03
OSV
CVE-2016-8568: The git_commit_message function in oid2017-02-03

📋Vendor Advisories

2
Ubuntu
libgit2 vulnerabilities2021-03-15
Debian
CVE-2016-8568: cargo - The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote ...2016

💬Community

3
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files [fedora-all]2016-10-10
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files [epel-all]2016-10-10
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files2016-10-10