VulnerabilityModified
CVE-2016-2315
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CRITICAL 9.8EPSS 17.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.31% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- suse/linux enterprise debuginfo · suse/openstack cloud · opensuse/leap · opensuse/opensuse · suse/linux enterprise server · suse/linux enterprise software development kit · suse/suse linux enterprise server · git-scm/git
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183147.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179121.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180763.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00059.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00060.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00062.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00071.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00074.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00076.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00077.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00011.htmlMailing List, Vendor Advisory
- http://pastebin.com/UX2P2jjgThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0496.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3521Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/03/15/5Mailing List
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.securityfocus.com/bid/84355Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035290Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2938-1Third Party Advisory
- https://github.com/git/git/commit/34fa79a6cde56d6d428ab0d3160cb094ebad3305Patch, Third Party Advisory
- https://github.com/git/git/commit/de1e67d0703894cb6ea782e36abb63976ab07e60Patch, Third Party Advisory
- https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.7.4.txtVendor Advisory
- https://security.gentoo.org/glsa/201605-01Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183147.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179121.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180763.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00059.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00060.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.