CVE-2016-2324: Buffer Overflow
Published Apr 8, 2016
·Updated
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
Affected Software
10 affected components
SUSE Linux Enterprise Debuginfo=11-sp4
SUSE Openstack Cloud=5
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Server=12.0-sp1
SUSE Linux Enterprise Software Development Kit=11-sp4
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Software Development Kit=12.0-sp1
SUSE SUSE Linux Enterprise Server=12
git-scm Git<=2.7.3
Remediation
Event History
Apr 8, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2324?
CVE-2016-2324 has a high severity level due to the potential for remote code execution.
2
How do I fix CVE-2016-2324?
To fix CVE-2016-2324, upgrade Git to version 2.7.4 or later.
3
What versions of Git are affected by CVE-2016-2324?
CVE-2016-2324 affects all versions of Git before 2.7.4.
4
Can CVE-2016-2324 be exploited remotely?
Yes, CVE-2016-2324 can be exploited remotely via long filenames or nested trees.
5
What types of systems are affected by CVE-2016-2324?
CVE-2016-2324 affects various SUSE and openSUSE systems that use vulnerable versions of Git.