LWN.net Logo

cgit: code execution

Package(s):cgit CVE #(s):CVE-2012-4465
Created:October 31, 2012 Updated:November 28, 2012
Description: From the CVE entry:

Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.

Alerts:
openSUSE openSUSE-SU-2012:1421-1 2012-10-31
openSUSE openSUSE-SU-2012:1422-1 2012-10-31
Fedora FEDORA-2012-18462 2012-11-28
Fedora FEDORA-2012-18464 2012-11-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds