NULL pointer dereference in libgit2 - CVE-2016-8569
Published: February 3, 2017 / Updated: January 22, 2023
Vulnerability identifier: #VU32004
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8569
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via a cat-file command with a crafted object file.
Affected software
libgit2
Arch Linux
Fedora
libgit2-0.27 (Alpine package)
libgit2-1.0 (Alpine package)
libgit2
Arch Linux
Fedora
libgit2-0.27 (Alpine package)
libgit2-1.0 (Alpine package)
libgit2
How to mitigate CVE-2016-8569
Install update from vendor's website.
libgit2-1.0 (Alpine package) - update to 1.0.1-r1
libgit2 - addressed in versions 0.23.4-2.fc23, 0.24.2-2.fc24, 0.24.2-2.fc25, 0.26.3-1.fc27, 0.26.3-1.fc28
libgit2 - addressed in versions 0.23.4-2.fc23, 0.24.2-2.fc24, 0.24.2-2.fc25, 0.26.3-1.fc27, 0.26.3-1.fc28
External References
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00075.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00103.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00110.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00114.html
- http://www.openwall.com/lists/oss-security/2016/10/08/7
- http://www.securityfocus.com/bid/93465
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://github.com/libgit2/libgit2/issues/3937
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4E77DG5KGQ7L34U75QY7O6NIPKZNQHQJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3JBSNJAXP7JA3TGE2NPNRTD77JXFG4E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XVUEIG6EESZB6BRU2IE3F5NRUEHMAEKC/
Related Security Bulletins
- NULL pointer dereference in libgit2.github.com libgit2
- NULL pointer dereference in libgit2-0.27 (Alpine package)
- Arch Linux update for libgit2
- NULL pointer dereference in libgit2-1.0 (Alpine package)
- Fedora 24 update for libgit2
- Fedora 23 update for libgit2
- Fedora 25 update for libgit2
- Fedora 28 update for libgit2
- Fedora 27 update for libgit2