CVE-2016-8569: Null Pointer Dereference
Published Feb 3, 2017
·Updated
The gitoidnfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
Affected Software
8 affected components
Libgit2 Project Libgit2<=0.24.2
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Fedoraproject Fedora=25
openSUSE Leap=42.1
openSUSE Leap=42.2
openSUSE openSUSE=13.2
SUSE Linux Enterprise=12.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8569?
CVE-2016-8569 has a severity rating that can lead to a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2016-8569?
To fix CVE-2016-8569, upgrade libgit2 to version 0.24.3 or later.
3
Which software versions are affected by CVE-2016-8569?
CVE-2016-8569 affects libgit2 versions before 0.24.3 and specific Fedora and openSUSE releases.
4
What type of vulnerability is CVE-2016-8569?
CVE-2016-8569 is classified as a denial of service vulnerability.
5
Can CVE-2016-8569 be exploited remotely?
Yes, CVE-2016-8569 can be exploited by remote attackers using a crafted object file with the cat-file command.