Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg34-58mc-jr2w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

EPSS

Процентиль: 89%
0.03746
Низкий

Дефекты

CWE-193

Связанные уязвимости

nvd
больше 15 лет назад

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

EPSS

Процентиль: 89%
0.03746
Низкий

Дефекты

CWE-193