Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-util/git. | Oct 30, 2017 | Aug 7, 2008 |
| Suse | — | Upgrade git-emailUpgrade git-coreUpgrade git-svnUpgrade suse-releaseUpgrade git-archUpgrade gitUpgrade gitkUpgrade git-cvs | Dec 12, 2013 | Aug 7, 2008 |
| Ubuntu | — | Upgrade gitwebUpgrade git-core | Nov 8, 2024 | Aug 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub