Unrated severityNVD Advisory· Published Mar 14, 2018· Updated Aug 5, 2024
CVE-2018-8099
CVE-2018-8099
Description
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
Affected products
3- osv-coords3 versionspkg:rpm/suse/libgit2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libgit2&distro=SUSE%20Manager%20Server%203.1pkg:rpm/suse/libgit2&distro=SUSE%20Manager%20Server%203.2
< 0.24.1-7.6.1+ 2 more
- (no CPE)range: < 0.24.1-7.6.1
- (no CPE)range: < 0.24.1-7.6.1
- (no CPE)range: < 0.24.1-7.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/libgit2/libgit2/commit/58a6fe94cb851f71214dbefac3f9bffee437d6femitrex_refsource_CONFIRM
- libgit2.github.com/security/mitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2022/03/msg00031.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.