CVE-2017-15298: Medium severity git-scm Git vulnerability
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-15298?
CVE-2017-15298 is a vulnerability in Git through 2.14.2 that mishandles layers of tree objects, allowing remote attackers to cause a denial of service (memory consumption).
How does CVE-2017-15298 impact disk consumption?
CVE-2017-15298 can also impact disk consumption, although an affected process typically would not survive its attempt to build a repository.
What is the severity of CVE-2017-15298?
CVE-2017-15298 has a severity rating of medium with a CVSS score of 5.5.
How can I fix CVE-2017-15298 on Ubuntu 14.04?
To fix CVE-2017-15298 on Ubuntu 14.04, update the 'git' package to version 1:1.9.1-1ubuntu0.10.
How can I fix CVE-2017-15298 on Ubuntu 16.04?
To fix CVE-2017-15298 on Ubuntu 16.04, update the 'git' package to version 2.7.4-0ubuntu1.6.