CVE-2016-1901: Buffer Overflow
Published Jan 20, 2016
·Updated
Integer overflow in the authenticatepost function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
Affected Software
2 affected components
Fedoraproject Fedora=22
Cgit Project Cgit<=0.11.2
Remediation
Patch Available
Event History
Jan 20, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1901?
CVE-2016-1901 is classified as a high severity vulnerability due to its potential for remote code execution through a buffer overflow.
2
How do I fix CVE-2016-1901?
To fix CVE-2016-1901, upgrade CGit to version 0.12 or newer.
3
What software is affected by CVE-2016-1901?
CVE-2016-1901 affects CGit versions up to and including 0.11.2 and Fedora 22.
4
What type of vulnerability is CVE-2016-1901?
CVE-2016-1901 is an integer overflow vulnerability that can lead to a buffer overflow.
5
Can CVE-2016-1901 be exploited remotely?
Yes, CVE-2016-1901 can be exploited remotely by sending a crafted HTTP request with a large Content-Length header.