Out-of-Bound Read Flaw in libgit2 Affects Multiple Versions
CVE-2018-10888

6.5MEDIUM

Key Information:

Vendor

Libgit2

Status
Vendor
CVE Published:
10 July 2018

What is CVE-2018-10888?

A flaw in libgit2 prior to version 0.27.3 is associated with a missing check in the git_delta_apply function within the delta.c file. This vulnerability can be exploited by attackers to trigger out-of-bound reads when processing a binary delta file. Successfully exploiting this flaw may lead to a Denial of Service, disrupting normal operations and potentially impacting service availability.

Affected Version(s)

libgit2 before version 0.27.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.