Описание
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 1:2.17.0-1ubuntu1 |
| cosmic | not-affected | 1:2.17.0-1ubuntu1 |
| devel | not-affected | 1:2.17.0-1ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1:1.9.1-1ubuntu0.10]] |
| esm-infra/bionic | not-affected | 1:2.17.0-1ubuntu1 |
| esm-infra/xenial | released | 1:2.7.4-0ubuntu1.6 |
| precise/esm | DNE | |
| trusty | released | 1:1.9.1-1ubuntu0.10 |
| trusty/esm | DNE | trusty was released [1:1.9.1-1ubuntu0.10] |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
Git through 2.14.2 mishandles layers of tree objects, which allows rem ...
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3