Denial of Service Vulnerability in libgit2 Affects Multiple Vendors
CVE-2016-8569

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 February 2017

What is CVE-2016-8569?

The git_oid_nfmt function in commit.c within libgit2 versions prior to 0.24.3 is susceptible to a denial of service due to a NULL pointer dereference. This vulnerability can be exploited by remote attackers through a crafted object file sent via the cat-file command. An effective attack can lead to unexpected behavior and application crashes, making it essential for users to update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.