Heap-based buffer overflow in Git - CVE-2016-2324
Published: April 8, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Integer overflow in Git before 2.7.4. A remote attacker can use a to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
SUSE Linux
Slackware Linux
Opensuse
git (Alpine package)
git
How to mitigate CVE-2016-2324
git (Alpine package) - update to 2.4.11-r0
git - addressed in versions 1.8.2.3-1.el5, 2.4.11-1.fc22, 2.5.5-1.fc23, 2.7.4-1.fc24
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183147.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179121.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/180763.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00062.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00071.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00074.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00077.html
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00011.html
- http://pastebin.com/UX2P2jjg
- http://rhn.redhat.com/errata/RHSA-2016-0496.html
- http://www.debian.org/security/2016/dsa-3521
- http://www.openwall.com/lists/oss-security/2016/03/15/5
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/84355
- http://www.securitytracker.com/id/1035290
- http://www.ubuntu.com/usn/USN-2938-1
- https://github.com/git/git/commit/de1e67d0703894cb6ea782e36abb63976ab07e60
- https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.7.4.txt
- https://security.gentoo.org/glsa/201605-01
Related Security Bulletins
- Heap-based buffer overflow in Git
- OpenSUSE Linux update for cgit
- OpenSUSE Linux update for git
- SUSE Linux update for git
- Heap-based buffer overflow in git (Alpine package)
- Amazon Linux AMI update for git
- Gentoo update for Git
- Slackware Linux update for git
- Slackware Linux update for git
- Fedora 23 update for git
- Fedora 22 update for git
- Fedora 24 update for git
- Fedora EPEL 5 update for git