VYPR
Medium severity5.9NVD Advisory· Published Mar 24, 2017· Updated May 13, 2026

CVE-2016-10130

CVE-2016-10130

Description

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

Affected products

4
  • cpe:2.3:a:libgit2_project:libgit2:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:libgit2_project:libgit2:*:*:*:*:*:*:*:*range: <=0.24.5
    • cpe:2.3:a:libgit2_project:libgit2:0.25.0:*:*:*:*:*:*:*
    • cpe:2.3:a:libgit2_project:libgit2:0.25.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:libgit2_project:libgit2:0.25.0:rc2:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.