CVE-2018-10887
Summary
| CVE | CVE-2018-10887 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-10 14:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service. |
Risk And Classification
Problem Types: CWE-125 | CWE-190 | CWE-681
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Libgit2 | Libgit2 | All | All | All | All |
| Application | Libgit2 | Libgit2 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release libgit2 v0.27.3 · libgit2/libgit2 · GitHub | CONFIRM | github.com | Patch, Release Notes, Third Party Advisory |
| [SECURITY] [DLA 2936-1] libgit2 security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 1477-1] libgit2 security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| delta: fix overflow when computing limit · libgit2/libgit2@c157711 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| delta: fix sign-extension of big left-shift · libgit2/libgit2@3f46190 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| 1598021 – (CVE-2018-10887) CVE-2018-10887 libgit2: integer overflow leads to out-of-bounds read in git_delta_apply, allowing to read before base array | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.