Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15298

Опубликовано: 12 окт. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jgitWill not fix
Red Hat Enterprise Linux 6gitWill not fix
Red Hat Enterprise Linux 7gitWill not fix
Red Hat JBoss A-MQ 6fabric8Will not fix
Red Hat JBoss BRMS 6jgitWill not fix
Red Hat JBoss Data Virtualization 6jgitWill not fix
Red Hat JBoss Fuse 6camelWill not fix
Red Hat JBoss Fuse Service Works 6jgitWill not fix
Red Hat Mobile Application Platform 4fh-scmWill not fix
Red Hat Software Collectionsrh-git29-gitWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1510455git: Mishandling layers of tree objects

EPSS

Процентиль: 63%
0.00446
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

CVSS3: 5.5
nvd
больше 8 лет назад

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

CVSS3: 5.5
debian
больше 8 лет назад

Git through 2.14.2 mishandles layers of tree objects, which allows rem ...

suse-cvrf
почти 8 лет назад

Security update for git

CVSS3: 5.5
github
больше 3 лет назад

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

EPSS

Процентиль: 63%
0.00446
Низкий

3.3 Low

CVSS3