CPANSA-Git-XS-X-libgit2-2015-0001-libgit2: Git-XS vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2015-01-20T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2015-01-20T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | Critical | |
Original language | Language | en | |
Also referred to |
Vulnerability Description
On the heels of CVE 2014-9390, we are announcing another round of security updates to libgit2. Similar to the prior vulnerability, an attacker can construct a git commit that, when checked out, may cause files to be written to your .git directory which may lead to arbitrary code execution.
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Git-XS-X-libgit2-2015-0001-libgit2 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2015/cpansa-git-xs-x-libgit2-2015-0001-libgit2.json - https://www.edwardthomson.com/blog/another-libgit2-security-update.html external
https://www.edwardthomson.com/blog/another-libgit2-security-update.html - X-libgit2-2015-0001 (NVD) external
https://nvd.nist.gov/vuln/detail/X-libgit2-2015-0001
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Tue Jan 20 00:00:00 2015 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/