cbcvebase.
CVE-2018-10887
published 2018-07-10

CVE-2018-10887: A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may…

PriorityP335high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
2.05%
79.1th percentile
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlibgit2< libgit2 0.27.4+dfsg.1-0.1 (bookworm)libgit2 0.27.4+dfsg.1-0.1 (bookworm)
libgit2libgit2< 0.27.30.27.3
libgit2libgit2
libgit2libgit2>= 0 < 0.27.4+dfsg.1-0.10.27.4+dfsg.1-0.1
libgit2libgit2>= 0 < 0.27.4+dfsg.1-0.10.27.4+dfsg.1-0.1
libgit2libgit2>= 0 < 0.27.4+dfsg.1-0.10.27.4+dfsg.1-0.1
libgit2libgit2>= 0 < 0.27.4+dfsg.1-0.10.27.4+dfsg.1-0.1

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.