CVE-2016-10128: Buffer Overflow
Buffer overflow in the gitpktparseline function in transports/smartpkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cargoto a version that resolves this vulnerability.Fixed in 0.47.0-3Fixed in 0.66.0+ds1-1 - Upgrade
Upgrade
debian/libgit2to a version that resolves this vulnerability.Fixed in 1.1.0+dfsg.1-4+deb11u2Fixed in 1.5.1+ds-1+deb12u1Fixed in 1.9.0+ds-2Fixed in 1.9.6+ds-1 - Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in 0.24.6 - Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in 0.25.1
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10128?
CVE-2016-10128 is considered to have a medium severity due to the potential for remote attacks through crafted packets.
How do I fix CVE-2016-10128?
Fix CVE-2016-10128 by upgrading to libgit2 version 0.24.6 or 0.25.1 or later.
What type of vulnerability is CVE-2016-10128?
CVE-2016-10128 is a buffer overflow vulnerability found in the git_pkt_parse_line function of libgit2.
Which versions of libgit2 are affected by CVE-2016-10128?
CVE-2016-10128 affects libgit2 versions prior to 0.24.6 and version 0.25.0.
Can CVE-2016-10128 be exploited remotely?
Yes, CVE-2016-10128 can be exploited remotely via a crafted non-flush packet.