CVE-2008-3546: Buffer Overflow
Stack-based buffer overflow in the (1) diffaddremove and (2) diffchange functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATHMAX when running GIT utilities such as git-diff or git-grep.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3546?
CVE-2008-3546 is a high-severity vulnerability due to a stack-based buffer overflow that can allow arbitrary code execution.
How do I fix CVE-2008-3546?
To fix CVE-2008-3546, upgrade GIT to version 1.5.6.4 or later.
Which versions of GIT are affected by CVE-2008-3546?
CVE-2008-3546 affects GIT versions prior to 1.5.6.4, including versions 1.5.5.3, 1.5.5.4, 1.5.6.1, 1.5.6.2, and 1.5.6.3.
Can CVE-2008-3546 be exploited remotely?
CVE-2008-3546 is a local vulnerability, requiring access to the system for exploitation.
What systems are primarily impacted by CVE-2008-3546?
CVE-2008-3546 primarily impacts systems running affected versions of GIT, like Linux distributions using outdated versions.