CVE-2016-2315: Buffer Overflow
Published Apr 8, 2016
·Updated
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
Affected Software
10 affected components
SUSE Linux Enterprise Debuginfo=11-sp4
SUSE Openstack Cloud=5
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12-sp1
SUSE SUSE Linux Enterprise Server=12
git-scm Git=2.7.3
Remediation
Event History
Apr 8, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2315?
CVE-2016-2315 is considered a critical vulnerability due to its potential for remote code execution via a heap-based buffer overflow.
2
How do I fix CVE-2016-2315?
To fix CVE-2016-2315, upgrade Git to version 2.7.4 or later immediately.
3
What software is affected by CVE-2016-2315?
CVE-2016-2315 affects multiple software versions including Git version 2.7.3 and various SUSE and openSUSE distributions.
4
What type of vulnerability is CVE-2016-2315?
CVE-2016-2315 is classified as a heap-based buffer overflow vulnerability.
5
Could CVE-2016-2315 lead to data compromise?
Yes, CVE-2016-2315 could lead to data compromise as it allows remote attackers to execute arbitrary code on the affected system.