A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2-1.1Upgrade libgit2-0.27Upgrade libgit2Upgrade libgit2-1.0 | Aug 22, 2024 | Jul 10, 2018 |
| Debian | — | Upgrade libgit2 | Feb 19, 2019 | Jul 10, 2018 |
| Freebsd | — | Upgrade libgit2 | Jul 12, 2018 | Jul 11, 2018 |
| Suse | — | Upgrade libgit2-24Upgrade libgit2-develUpgrade libgit2-26Upgrade libgit2-26-32bitUpgrade libgit2-28 | Aug 25, 2018 | Jul 10, 2018 |
| Ubuntu | — | Upgrade libgit2 | Nov 19, 2024 | Jul 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub