Integer Overflow Vulnerability in libgit2 Affects Various Git-Related Applications
CVE-2018-8098

6.5MEDIUM

Key Information:

Vendor

Libgit2

Status
Vendor
CVE Published:
14 March 2018

What is CVE-2018-8098?

An integer overflow vulnerability exists in the libgit2 library, specifically within the index.c:read_entry() function. This flaw arises while decompressing compressed prefix lengths and can be exploited by an attacker through a specially crafted repository index file. If successfully executed, it may result in a denial of service, leading to out-of-bounds reads and potential disruption of services relying on the affected library.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.