Out-of-bounds read in libgit2 - CVE-2018-10888
Published: July 12, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to a missing check in the git_delta_apply function, as defined in the delta.c file. A remote unauthenticated attacker can trick the victim into opening a specially crafted binary delta file, trigger an out-of-bounds read condition and cause the service to crash.
Affected software
libgit2-0.27 (Alpine package)
libgit2-1.0 (Alpine package)
libgit2
Fedora
Opensuse
How to mitigate CVE-2018-10888
libgit2-1.0 (Alpine package) - update to 1.0.1-r1
libgit2 - addressed in versions 0.26.5-1.el7, 0.26.5-1.fc27, 0.26.5-1.fc28