Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg34-58mc-jr2w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

EPSS

Процентиль: 90%
0.05194
Низкий

Дефекты

CWE-193

Связанные уязвимости

nvd
почти 15 лет назад

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

EPSS

Процентиль: 90%
0.05194
Низкий

Дефекты

CWE-193