CPANSA-Git-Raw-2018-10887-libgit2: Git-Raw vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2018-07-10T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2018-07-10T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 8.1 | Severity | High |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
Vulnerabilities
CVE-2018-10887
Vulnerability DescriptionA flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
| Weakness | CWE-194 : Unexpected Sign Extension |
|---|
Product status
Known affected
| Product | Score | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Git-Raw greater than or equal 0.76 and less than or equal 0.82 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Git-Raw-2018-10887-libgit2 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2018/cpansa-git-raw-2018-10887-libgit2.json - https://github.com/libgit2/libgit2/releases/tag/v0.27.3 external
https://github.com/libgit2/libgit2/releases/tag/v0.27.3 - https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22 external
https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22 - https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a external
https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a - https://bugzilla.redhat.com/show_bug.cgi?id=1598021 external
https://bugzilla.redhat.com/show_bug.cgi?id=1598021 - https://lists.debian.org/debian-lts-announce/2018/08/msg00024.html external
https://lists.debian.org/debian-lts-announce/2018/08/msg00024.html - https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html external
https://lists.debian.org/debian-lts-announce/2022/03/msg00031.html - CVE-2018-10887 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2018-10887
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Tue Jul 10 00:00:00 2018 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/