Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11233

Опубликовано: 30 мая 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

Отчет

This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11jgitWill not fix
Red Hat Enterprise Linux 6gitNot affected
Red Hat Enterprise Linux 7gitNot affected
Red Hat Enterprise Linux 8gitNot affected
Red Hat Fuse 7camelNot affected
Red Hat JBoss A-MQ 6jgitNot affected
Red Hat JBoss BRMS 6jgitNot affected
Red Hat JBoss Data Virtualization 6jgitNot affected
Red Hat JBoss Fuse 6camelNot affected
Red Hat JBoss Fuse Integration Service 2camelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1583888git: path sanity check in is_ntfs_dotgit() can read arbitrary memory

EPSS

Процентиль: 51%
0.00276
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

CVSS3: 7.5
nvd
больше 7 лет назад

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

CVSS3: 7.5
debian
больше 7 лет назад

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16 ...

CVSS3: 7.5
github
больше 3 лет назад

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

suse-cvrf
больше 7 лет назад

Security update for git

EPSS

Процентиль: 51%
0.00276
Низкий

5.3 Medium

CVSS3