Логотип exploitDog
bind:"CVE-2024-24575"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-24575"

Количество 8

Количество 8

ubuntu логотип

CVE-2024-24575

почти 2 года назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-24575

почти 2 года назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-24575

почти 2 года назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-24575

почти 2 года назад

libgit2 is vulnerable to a denial of service attack in `git_revparse_single`

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-24575

почти 2 года назад

libgit2 is a portable C implementation of the Git core methods provide ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-01378

почти 2 года назад

Уязвимость компонента src/libgit2/revparse.c реализации методов Git на языке C Libgit2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2584-1

больше 1 года назад

Security update for libgit2

EPSS: Низкий
redos логотип

ROS-20240410-13

больше 1 года назад

Множественные уязвимости libgit2

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-24575

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-24575

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-24575

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in `src/libgit2/revparse.c` uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-24575

libgit2 is vulnerable to a denial of service attack in `git_revparse_single`

CVSS3: 7.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-24575

libgit2 is a portable C implementation of the Git core methods provide ...

CVSS3: 7.5
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-01378

Уязвимость компонента src/libgit2/revparse.c реализации методов Git на языке C Libgit2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:2584-1

Security update for libgit2

больше 1 года назад
redos логотип
ROS-20240410-13

Множественные уязвимости libgit2

CVSS3: 9.8
больше 1 года назад

Уязвимостей на страницу