CVE-2016-10129
Summary
| CVE | CVE-2016-10129 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-24 15:59:00 UTC |
| Updated | 2017-03-28 01:59:00 UTC |
| Description | The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| openSUSE-SU-2017:0484-1: moderate: Security update for libgit2 |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| libgit2 |
CONFIRM |
libgit2.github.com |
Patch, Vendor Advisory |
| oss-security - CVE Request: two security fixes in libgit2 0.25.1, 0.24.6 |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| openSUSE-SU-2017:0397-1: moderate: Security update for libgit2 |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| smart_pkt: treat empty packet lines as error · libgit2/libgit2@84d30d5 · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| oss-security - Re: CVE Request: two security fixes in libgit2 0.25.1, 0.24.6 |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| libgit2 Multiple NULL Pointer Dereference Remote Code Execution Vulnerability |
BID |
www.securityfocus.com |
|
| openSUSE-SU-2017:0405-1: moderate: Security update for libgit2 |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| smart_pkt: treat empty packet lines as error · libgit2/libgit2@2fdef64 · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501035 Alpine Linux Security Update for libgit2
- 501600 Alpine Linux Security Update for libgit2-1.0
- 502109 Alpine Linux Security Update for libgit2-1.1
- 504998 Alpine Linux Security Update for libgit2