First published: Thu Aug 07 2008(Updated: )
Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TUBITAK BILGEM Pardus OS | =2007 | |
TUBITAK BILGEM Pardus OS | =2008 | |
Git | =1.5.5.3 | |
Git | =1.5.5.3-r1 | |
Git | =1.5.5.4 | |
Git | =1.5.6.1 | |
Git | =1.5.6.2 | |
Git | =1.5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3546 is a high-severity vulnerability due to a stack-based buffer overflow that can allow arbitrary code execution.
To fix CVE-2008-3546, upgrade GIT to version 1.5.6.4 or later.
CVE-2008-3546 affects GIT versions prior to 1.5.6.4, including versions 1.5.5.3, 1.5.5.4, 1.5.6.1, 1.5.6.2, and 1.5.6.3.
CVE-2008-3546 is a local vulnerability, requiring access to the system for exploitation.
CVE-2008-3546 primarily impacts systems running affected versions of GIT, like Linux distributions using outdated versions.