Vulnerability CVE-2012-4465


Published: 2012-10-10   Modified: 2012-10-11

Description:
Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Lars hjemli -> CGIT 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=820733
http://www.openwall.com/lists/oss-security/2012/10/03/7
http://www.openwall.com/lists/oss-security/2012/09/30/1
http://secunia.com/advisories/50734
http://hjemli.net/pipermail/cgit/2012-July/000652.html
http://git.zx2c4.com/cgit/commit/?id=7757d1b046ecb67b830151d20715c658867df1ec

Copyright 2024, cxsecurity.com

 

Back to Top