Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2324

Опубликовано: 06 мар. 2016
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

An integer truncation flaw and an integer overflow flaw, both leading to a heap-based buffer overflow, were found in the way Git processed certain path information. A remote attacker could create a specially crafted Git repository that would cause a Git client or server to crash or, possibly, execute arbitrary code.

Отчет

Red Hat Product Security has rated these issues as having Important security impact. For additional information, refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/2201201

Дополнительная информация

Статус:

Important
Дефект:
CWE-131->CWE-122->CWE-190->CWE-194
https://bugzilla.redhat.com/show_bug.cgi?id=1317981git: path_name() integer truncation and overflow leading to buffer overflow

EPSS

Процентиль: 97%
0.35462
Средний

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

CVSS3: 9.8
nvd
больше 9 лет назад

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

CVSS3: 9.8
debian
больше 9 лет назад

Integer overflow in Git before 2.7.4 allows remote attackers to execut ...

CVSS3: 9.8
github
больше 3 лет назад

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

fstec
больше 9 лет назад

Уязвимость распределенной системы управления версиями Git, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.35462
Средний

6.8 Medium

CVSS2