|
|
Subscribe / Log in / New account

Arch Linux alert ASA-201611-17 (libgit2)

From:  Levente Polyak <anthraxx@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [arch-security] [ASA-201611-17] libgit2: denial of service
Date:  Wed, 16 Nov 2016 18:07:04 +0100
Message-ID:  <41063298-8e48-c732-c727-5d5db15b64ad@archlinux.org>

Arch Linux Security Advisory ASA-201611-17 ========================================== Severity: Low Date : 2016-11-16 CVE-ID : CVE-2016-8568 CVE-2016-8569 Package : libgit2 Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/index.php/CVE Summary ======= The package libgit2 before version 1:0.24.3-1 is vulnerable to denial of service. Resolution ========== Upgrade to 1:0.24.3-1. # pacman -Syu "libgit2>=1:0.24.3-1" The problems have been fixed upstream in version 0.24.3. Workaround ========== None. Description =========== - CVE-2016-8568 (denial of service) A heap-based read out-of-bounds access has been discovered while parsing a malformed object file. - CVE-2016-8569 (denial of service) A null pointer dereference has been discovered while showing a malformed object file. Impact ====== A remote attacker is able to create specially crafted object files that lead to an application crash resulting in denial of service. References ========== http://seclists.org/oss-sec/2016/q4/64 https://github.com/libgit2/libgit2/issues/3936 https://github.com/libgit2/libgit2/issues/3937 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8568 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8569


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds