[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-10887 -- libgit2

ID: oval:org.secpod.oval:def:2000286Date: (C)2019-04-21   (M)2024-02-19
Class: VULNERABILITYFamily: unix




A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.

Platform:
Debian 8.x
Debian 9.x
Product:
libgit2-dev
Reference:
CVE-2018-10887
CVE    1
CVE-2018-10887
CPE    4
cpe:/a:libgit2:libgit2-dev
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies