CVE-2018-15501
published 2018-08-18CVE-2018-15501: In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.34%
90.2th percentile
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgit2 | < libgit2 0.27.4+dfsg.1-0.1 (bookworm) | libgit2 0.27.4+dfsg.1-0.1 (bookworm) |
| libgit2 | libgit2 | < 0.26.6 | 0.26.6 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0 < 0.27.4+dfsg.1-0.1 | 0.27.4+dfsg.1-0.1 |
| libgit2 | libgit2 | >= 0.27.0 < 0.27.4 | 0.27.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libgit2: out-of-bounds reads when processing smart-protocol ng packets
vendor_redhat·2018-08-07·CVSS 7.5
CVE-2018-15501 [HIGH] CWE-125 libgit2: out-of-bounds reads when processing smart-protocol ng packets
libgit2: out-of-bounds reads when processing smart-protocol ng packets
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
Package: libgit2 (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-15501: libgit2 - In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0...
vendor_debian·2018·CVSS 7.5
CVE-2018-15501 [HIGH] CVE-2018-15501: libgit2 - In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0...
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
Scope: local
bookworm: resolved (fixed in 0.27.4+dfsg.1-0.1)
bullseye: resolved (fixed in 0.27.4+dfsg.1-0.1)
forky: resolved (fixed in 0.27.4+dfsg.1-0.1)
sid: resolved (fixed in 0.27.4+dfsg.1-0.1)
trixie: resolved (fixed in 0.27.4+dfsg.1-0.1)
GHSA
GHSA-432h-4cw6-prpw: In ng_pkt in transports/smart_pkt
ghsa_unreviewed·2022-05-12
CVE-2018-15501 [HIGH] CWE-125 GHSA-432h-4cw6-prpw: In ng_pkt in transports/smart_pkt
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
OSV
CVE-2018-15501: In ng_pkt in transports/smart_pkt
osv·2018-08-18·CVSS 7.5
CVE-2018-15501 [HIGH] CVE-2018-15501: In ng_pkt in transports/smart_pkt
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [fedora-all]
bugzilla·2018-08-13·CVSS 7.5
CVE-2018-15501 [HIGH] CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [fedora-all]
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [epel-all]
bugzilla·2018-08-13·CVSS 7.5
CVE-2018-15501 [HIGH] CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [epel-all]
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets
bugzilla·2018-08-13·CVSS 7.5
CVE-2018-15501 [HIGH] CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets
CVE-2018-15501 libgit2: out-of-bounds reads when processing smart-protocol ng packets
A flaw was found in libgit2, an out of bounds read when parsing an "ng" packet. libgit2 keeps track of both the current position as well as the remaining length of the packet itself. But instead of taking care not to exceed the length, libgit2 passs the current pointer's position to strchr, which will search for a certain character until hitting NUL. It is thus possible to create a crafted packet which doesn't contain a NUL byte to trigger an out-of-bounds read.
References:
https://bugs.gentoo.org/662994
Upstream fix:
https://github.com/libgit2/libgit2/commit/1f9a8510e1d2f20ed7334eeeddb92c4dd8e7c649
Discussion:
Created libgit2 tracking bugs for this issue:
Affects: epel-all [bug 1615589]
Affects: f
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9406https://bugzilla.suse.com/show_bug.cgi?id=1104641https://github.com/libgit2/libgit2/commit/1f9a8510e1d2f20ed7334eeeddb92c4dd8e7c649https://github.com/libgit2/libgit2/releases/tag/v0.26.6https://github.com/libgit2/libgit2/releases/tag/v0.27.4https://lists.debian.org/debian-lts-announce/2018/08/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlhttps://www.pro-linux.de/sicherheit/2/44650/denial-of-service-in-libgit2.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9406https://bugzilla.suse.com/show_bug.cgi?id=1104641https://github.com/libgit2/libgit2/commit/1f9a8510e1d2f20ed7334eeeddb92c4dd8e7c649https://github.com/libgit2/libgit2/releases/tag/v0.26.6https://github.com/libgit2/libgit2/releases/tag/v0.27.4https://lists.debian.org/debian-lts-announce/2018/08/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlhttps://www.pro-linux.de/sicherheit/2/44650/denial-of-service-in-libgit2.html
2018-08-18
Published