CVE-2018-10887
published 2018-07-10CVE-2018-10887: A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may…
PriorityP335high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
2.05%
79.1th percentile
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgit2 | < libgit2 0.27.4+dfsg.1-0.1 (bookworm) | libgit2 0.27.4+dfsg.1-0.1 (bookworm) |
| libgit2 | libgit2 | < 0.27.3 | 0.27.3 |
| libgit2 | libgit2 | — | — |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-10887: libgit2 - A flaw was found in libgit2 before version 0.27.3. It has been discovered that a...
vendor_debian·2018·CVSS 8.1
CVE-2018-10887 [HIGH] CVE-2018-10887: libgit2 - A flaw was found in libgit2 before version 0.27.3. It has been discovered that a...
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 0.27.4+dfsg.1-0.1)
bullseye: resolved (fixed in 0.27.4+dfsg.1-0.1)
forky: resolved (fixed in 0.27.4+dfsg.1-0.1)
sid: resolved (fixed in 0.27.4+dfsg.1-0.1)
trixie: resolved (fixed in 0.27.4+dfsg.1-0.1)
GHSA
GHSA-5gcq-g5p3-pjp4: A flaw was found in libgit2 before version 0
ghsa_unreviewed·2022-05-13
CVE-2018-10887 [HIGH] CWE-125 GHSA-5gcq-g5p3-pjp4: A flaw was found in libgit2 before version 0
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
OSV
CVE-2018-10887: A flaw was found in libgit2 before version 0
osv·2018-07-10·CVSS 8.1
CVE-2018-10887 [HIGH] CVE-2018-10887: A flaw was found in libgit2 before version 0
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array [fedora-all]
bugzilla·2018-07-09·CVSS 8.1
CVE-2018-10887 [HIGH] CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array [fedora-all]
CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array
bugzilla·2018-07-04·CVSS 8.1
CVE-2018-10887 [HIGH] CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array
CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array
An unexpected sign extension in git_delta_apply function leads to an integer overflow in the bounds check, allowing to bypass it and to read some bytes before the `base` object. An attacker may use this flaw to get an information leak or cause a Denial of Service.
Discussion:
Acknowledgments:
Name: Riccardo Schirone (Product Security Red Hat)
---
Patch:
https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a
https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22
---
External References:
https://github.com/libgit2/libgit2/releases/tag/v0.27.3
---
Created libgit2 tracking bugs for this issue:
Affects: fe
CWE
Integer Overflow or Wraparound
mitre_cwe
CWE-190 Integer Overflow or Wraparound
CWE-190: Integer Overflow or Wraparound
The product performs a calculation that can
produce an integer overflow or wraparound when the logic
assumes that the resulting value will always be larger than
the original value. This occurs when an integer value is
incremented to a value that is too large to store in the
associated representation. When this occurs, the value may
become a very small or negative number.
Modes of Introduction:
Phase: Implementation
Note: This weakness may become security critical when determining the offset or size in behaviors such as memory allocation, copying, and concatenation.
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart, DoS: Resource Consumption (Memory), DoS: Instability. This weakness can generally lead to undefined behav
CWE
Unexpected Sign Extension
mitre_cwe
CWE-194 Unexpected Sign Extension
CWE-194: Unexpected Sign Extension
The product performs an operation on a number that causes it to be sign extended when it is transformed into a larger data type. When the original number is negative, this can produce unexpected values that lead to resultant weaknesses.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Confidentiality, Availability, Other. Impact: Read Memory, Modify Memory, Other. When an unexpected sign extension occurs in code that operates directly on memory buffers, such as a size value or a memory index, then it could cause the program to write or read outside the boundaries of the intended buffer. If the numeric value is associated with an application-level resource, such as a quantity or price for a product in an e-commerce sit
CWE
Out-of-bounds Read
mitre_cwe
CWE-125 Out-of-bounds Read
CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory. An attacker could get secret values such as cryptographic keys, PII, memory addresses, or other information that could be used in additional attacks.
Scope: Confidentiality. Impact: Bypass Protection Mechanism. Out-of-bounds memory could contain memory addresses or other information that can be used to bypass ASLR and other protection mechanisms in order to improve the reliability of exploiting a separate weakness for code execution.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. An attacker could cause a segmentation fault or crash by causing memory to
https://bugzilla.redhat.com/show_bug.cgi?id=1598021https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2ahttps://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22https://github.com/libgit2/libgit2/releases/tag/v0.27.3https://lists.debian.org/debian-lts-announce/2018/08/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1598021https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2ahttps://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22https://github.com/libgit2/libgit2/releases/tag/v0.27.3https://lists.debian.org/debian-lts-announce/2018/08/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00031.html
2018-07-10
Published