Wind River Support Network

HomeDefectsLIN10-2213
Fixed

LIN10-2213 : Security Advisory - git - CVE-2017-15298

Created: Oct 16, 2017    Updated: May 18, 2019
Resolved Date: Apr 17, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.16
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

https://nvd.nist.gov/vuln/detail/CVE-2017-15298

CVEs


Live chat
Online