CVE-2018-15501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
18/08/2018
Last modified:
11/05/2022

Description

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:* 0.26.6 (excluding)
cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:* 0.27.0 (including) 0.27.4 (excluding)