ALT-PU-2016-2254-1
Closed vulnerabilities
Published: 2017-02-03
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-8568
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2016:3097
- openSUSE-SU-2016:3097
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0208
- openSUSE-SU-2017:0208
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- 93466
- 93466
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://github.com/libgit2/libgit2/issues/3936
- https://github.com/libgit2/libgit2/issues/3936
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- FEDORA-2016-bc51f4636f
- FEDORA-2016-bc51f4636f
- FEDORA-2016-616a35205b
- FEDORA-2016-616a35205b
- FEDORA-2016-505d7fe198
- FEDORA-2016-505d7fe198
Published: 2017-02-03
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-8569
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2016:3097
- openSUSE-SU-2016:3097
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0208
- openSUSE-SU-2017:0208
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- 93465
- 93465
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://github.com/libgit2/libgit2/issues/3937
- https://github.com/libgit2/libgit2/issues/3937
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- FEDORA-2016-bc51f4636f
- FEDORA-2016-bc51f4636f
- FEDORA-2016-616a35205b
- FEDORA-2016-616a35205b
- FEDORA-2016-505d7fe198
- FEDORA-2016-505d7fe198