First published: Fri Feb 03 2017(Updated: )
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libgit2 | <=0.24.2 | |
Fedora | =23 | |
Fedora | =24 | |
Fedora | =25 | |
SUSE Linux | =42.1 | |
SUSE Linux | =42.2 | |
SUSE Linux | =13.2 | |
SUSE Linux Enterprise Server | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8569 has a severity rating that can lead to a denial of service due to a NULL pointer dereference.
To fix CVE-2016-8569, upgrade libgit2 to version 0.24.3 or later.
CVE-2016-8569 affects libgit2 versions before 0.24.3 and specific Fedora and openSUSE releases.
CVE-2016-8569 is classified as a denial of service vulnerability.
Yes, CVE-2016-8569 can be exploited by remote attackers using a crafted object file with the cat-file command.