VYPR

rpm package

opensuse/libgit2&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/libgit2&distro=openSUSE%20Tumbleweed

Vulnerabilities (29)

  • CVE-2018-17456CriOct 6, 2018
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '

  • CVE-2018-10887HigJul 10, 2018
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacke

  • CVE-2018-11235HigMay 30, 2018
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-subm

  • CVE-2018-8098MedMar 14, 2018
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.

  • CVE-2016-10130MedMar 24, 2017
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

  • CVE-2016-10128CriMar 24, 2017
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

  • CVE-2016-8569MedFeb 3, 2017
    affected < 0.24.3-1.1fixed 0.24.3-1.1

    The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

  • CVE-2016-8568MedFeb 3, 2017
    affected < 0.24.3-1.1fixed 0.24.3-1.1

    The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

  • CVE-2005-4900MedOct 14, 2016
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of

Page 2 of 2