Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10130

Опубликовано: 24 мар. 2017
Источник: debian
EPSS Низкий

Описание

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgit2fixed0.25.1+really0.24.6-1package
libgit2not-affectedjessiepackage
cargofixed0.17.0-1~exp1experimentalpackage
cargofixed0.17.0-1package

Примечания

  • https://github.com/libgit2/libgit2/commit/9a64e62f0f20c9cf9b2e1609f037060eb2d8eb22 (v0.25.1)

  • https://github.com/libgit2/libgit2/commit/b5c6a1b407b7f8b952bded2789593b68b1876211 (v0.24.6)

EPSS

Процентиль: 77%
0.01054
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 9 лет назад

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

CVSS3: 5.9
nvd
почти 9 лет назад

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

CVSS3: 5.9
github
больше 3 лет назад

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

suse-cvrf
почти 9 лет назад

Security update for libgit2

suse-cvrf
около 9 лет назад

Security update for libgit2

EPSS

Процентиль: 77%
0.01054
Низкий