First published: Wed Mar 14 2018(Updated: )
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libgit2 | <0.26.2 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-8099.
The title of the vulnerability is "Incorrect returning of an error code in the index.c:read_entry() function leads to a double free."
The vulnerability can cause a denial of service.
The affected software is Libgit2 (version up to exclusive 0.26.2) and Debian Linux (version 9.0).
The severity of this vulnerability is medium (CVSS score of 6.5).
To fix this vulnerability, update Libgit2 to version 0.26.2 or later and Debian Linux to a version higher than 9.0.