MGASA-2017-0319

Source
https://advisories.mageia.org/MGASA-2017-0319.html
Import Source
https://advisories.mageia.org/MGASA-2017-0319.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0319
Related
Published
2017-08-29T20:36:17Z
Modified
2017-08-29T20:15:32Z
Summary
Updated libgit2 packages fix security vulnerabilities
Details

Read out-of-bounds in gitoidnfmt (CVE-2016-8568).

DoS using a null pointer dereference in gitcommitmessage (CVE-2016-8569).

Insufficient sanitization allows some edge cases in the Git Smart Protocol which can lead to reading outside of a buffer (CVE-2016-10128, CVE-2016-10129).

References
Credits

Affected packages

Mageia:5 / libgit2

Package

Name
libgit2
Purl
pkg:rpm/mageia/libgit2?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.21.1-3.2.mga5

Ecosystem specific

{
    "section": "core"
}