CVE-2016-8569

Severity
5.5MEDIUM
EPSS
0.6%
top 31.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateMay 14

Description

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianlibgit2< 0.24.2-2+3
Debiancargo< 0.17.0-1+1
NVDopensuse/leap42.1, 42.2+1

Also affects: Fedora 23, 24, 25, Linux Enterprise 12.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m99c-3xxj-4mxh: The git_oid_nfmt function in commit2022-05-14
OSV
CVE-2016-8569: The git_oid_nfmt function in commit2017-02-03
CVEList
CVE-2016-8569: The git_oid_nfmt function in commit2017-02-03

📋Vendor Advisories

2
Ubuntu
libgit2 vulnerabilities2021-03-15
Debian
CVE-2016-8569: cargo - The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote att...2016

💬Community

3
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files [fedora-all]2016-10-10
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files [epel-all]2016-10-10
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files2016-10-10