CVE-2016-8568
Read out-of-bounds in gitoidnfmt: https://github.com/libgit2/libgit2/issues/3936
CVE-2016-8569
DoS using a null pointer dereference in gitcommitmessage: https://github.com/libgit2/libgit2/issues/3937
Proposed patch:
https://github.com/libgit2/libgit2/pull/3956
The gitoidnfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.