Lucene search

K
freebsdFreeBSD43768FF3-C683-11EE-97D0-001B217B3468
HistoryFeb 06, 2024 - 12:00 a.m.

Libgit2 -- multiple vulnerabilities

2024-02-0600:00:00
vuxml.freebsd.org
12
vulnerabilities
infinite loop
out-of-bounds read
libgit2
security fix
denial of service
smart transport
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%

Git community reports:

A bug in git_revparse_single is fixed that could have caused the function to enter an infinite loop given well-crafted inputs, potentially causing a Denial of Service attack in the calling application
A bug in git_revparse_single is fixed that could have caused the function to enter an infinite loop given well-crafted inputs, potentially causing a Denial of Service attack in the calling application
A bug in the smart transport negotiation could have caused an out-of-bounds read when a remote server did not advertise capabilities

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarcheza< 0.18.2UNKNOWN
FreeBSDanynoarchlibgit2= 1.7.0UNKNOWN
FreeBSDanynoarchlibgit2< 1.7.2UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%