revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 30, 2017 | Apr 8, 2016 |
| Centos_linux | — | Upgrade git-hgUpgrade gitkUpgrade git-emailUpgrade perl-Git-SVNUpgrade git-svnUpgrade gitUpgrade git-cvsUpgrade git-bzrUpgrade git-p4Upgrade perl-GitUpgrade git-guiUpgrade gitwebUpgrade git-daemonUpgrade emacs-git-elUpgrade emacs-gitUpgrade git-all | Jul 6, 2016 | Mar 23, 2016 |
| Debian | — | Upgrade git | Mar 22, 2016 | Mar 19, 2016 |
| Freebsd | — | Upgrade git | Dec 10, 2025 | Mar 17, 2016 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Oct 30, 2017 | Apr 8, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Apr 8, 2016 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.7.4-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 8, 2016 |
| Oracle_linux | — | Upgrade emacs-git-elUpgrade git-allUpgrade gitUpgrade git-bzrUpgrade git-svnUpgrade perl-Git-SVNUpgrade gitwebUpgrade git-guiUpgrade git-hgUpgrade perl-GitUpgrade git-cvsUpgrade git-p4Upgrade gitkUpgrade emacs-gitUpgrade git-daemonUpgrade git-email | Apr 8, 2016 | Apr 8, 2016 |
| Suse | — | Upgrade git-archUpgrade git-docUpgrade git-cvsUpgrade git-emailUpgrade git-svnUpgrade git-coreUpgrade git-daemonUpgrade gitUpgrade git-guiUpgrade gitkUpgrade git-web | Mar 22, 2016 | Mar 16, 2016 |
| Ubuntu | — | Upgrade git | Mar 22, 2016 | Mar 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub