Integer Overflow in libgit2 Affects Multiple Applications
CVE-2018-10887

8.1HIGH

Key Information:

Vendor

Libgit2

Status
Vendor
CVE Published:
10 July 2018

What is CVE-2018-10887?

A flaw discovered in libgit2 prior to version 0.27.3 involves an unexpected sign extension in the git_delta_apply function within the delta.c file. This flaw can result in an integer overflow, potentially leading to an out of bounds read. As a consequence, attackers may exploit this vulnerability to leak sensitive memory addresses or trigger service interruptions. It’s essential to address this issue promptly by updating to the latest version to ensure system integrity and security.

Affected Version(s)

libgit2 before version 0.27.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.