CVE-2022-23521

CWE-190Integer Overflow15 documents8 sources
Severity
9.8CRITICAL
EPSS
12.3%
top 6.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 17
Latest updateMar 1

Description

Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5git/git< 2.30.7+9
Debiangit< 1:2.30.2-1+deb11u1+3
Ubuntugit< 1:2.17.1-1ubuntu0.15+6
NVDgit-scm/git2.31.02.31.5+9

Patches

🔴Vulnerability Details

6
OSV
git vulnerabilities2023-03-01
OSV
git vulnerabilities2023-02-07
OSV
git regression2023-01-19
CVEList
gitattributes parsing integer overflow in git2023-01-17
OSV
CVE-2022-23521: Git is distributed revision control system2023-01-17

📋Vendor Advisories

8
Ubuntu
Git vulnerabilities2023-03-01
Microsoft
GitHub: CVE-2022-23521 gitattributes parsing integer overflow2023-02-14
Jenkins
Jenkins Security Advisory 2023-02-092023-02-09
Ubuntu
Git vulnerabilities2023-02-07
Ubuntu
Git regression2023-01-19