cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
BID:46756
Info
cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
| Bugtraq ID: | 46756 |
| Class: | Unknown |
| CVE: |
CVE-2011-1027 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2011 12:00AM |
| Updated: | May 07 2015 05:16PM |
| Credit: | Jim Meyering |
| Vulnerable: |
cgit cgit 0.8.3.4 |
| Not Vulnerable: |
cgit cgit 0.8.3.5 |
Discussion
cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
cgit is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected to fall into an infinite loop, denying service to legitimate users.
Versions prior to cgit 0.8.3.5 are vulnerable.
cgit is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected to fall into an infinite loop, denying service to legitimate users.
Versions prior to cgit 0.8.3.5 are vulnerable.
Exploit / POC
cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to connect to a malicious software repository.
An attacker can exploit this issue by enticing an unsuspecting victim to connect to a malicious software repository.
Solution / Fix
cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
Solution:
The vendor released an update. Please see the references for more details.
Solution:
The vendor released an update. Please see the references for more details.
References
cgit 'convert_query_hexchar()' Remote Denial of Service Vulnerability
References:
References:
- do not infloop on a query ending in %XY, for invalid hex X or Y (Jim Meyering)
- Vendor Homepage (cgit)