Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2315

Опубликовано: 06 мар. 2016
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

An integer truncation flaw and an integer overflow flaw, both leading to a heap-based buffer overflow, were found in the way Git processed certain path information. A remote attacker could create a specially crafted Git repository that would cause a Git client or server to crash or, possibly, execute arbitrary code.

Отчет

Red Hat Product Security has rated these issues as having Important security impact. For additional information, refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/2201201

Дополнительная информация

Статус:

Important
Дефект:
CWE-131->CWE-122->CWE-190->CWE-194
https://bugzilla.redhat.com/show_bug.cgi?id=1317981git: path_name() integer truncation and overflow leading to buffer overflow

EPSS

Процентиль: 96%
0.2572
Средний

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 9 лет назад

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

CVSS3: 9.8
debian
больше 9 лет назад

revision.c in git before 2.7.4 uses an incorrect integer data type, wh ...

CVSS3: 9.8
github
больше 3 лет назад

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

fstec
больше 9 лет назад

Уязвимость распределенной системы управления версиями Git, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.2572
Средний

6.8 Medium

CVSS2