GIT Remote Buffer Overflow Vulnerability
BID:16417
Info
GIT Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 16417 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2006 12:00AM |
| Updated: | Feb 07 2006 08:56PM |
| Credit: | Discovered by Mark Wooding. |
| Vulnerable: |
GIT GIT 1.1.4 |
| Not Vulnerable: |
GIT GIT 1.1.5 |
Discussion
GIT Remote Buffer Overflow Vulnerability
GIT is prone to a remote buffer-overflow vulnerability.
The issue presents itself when a large symbolic link in an index file is processed. A successful attack may result in arbitrary code execution in the context of the user.
GIT is prone to a remote buffer-overflow vulnerability.
The issue presents itself when a large symbolic link in an index file is processed. A successful attack may result in arbitrary code execution in the context of the user.
Exploit / POC
GIT Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
GIT Remote Buffer Overflow Vulnerability
Solution:
The vendor has released GIT 1.1.5 to address this issue.
GIT GIT 1.1.4
Solution:
The vendor has released GIT 1.1.5 to address this issue.
GIT GIT 1.1.4
-
GIT git-1.1.5.tar.gz
http://www.kernel.org/pub/software/scm/git/git-1.1.5.tar.gz
References
GIT Remote Buffer Overflow Vulnerability
References:
References:
- GIT Homepage (GIT)
- Patch: GIT 1.1.5 (Junio C Hamano
)