Wind River Support Network

HomeDefectsLIN8-7975
Fixed

LIN8-7975 : Security Advisory - git - CVE-2017-15298

Created: Oct 16, 2017    Updated: May 15, 2019
Resolved Date: Apr 19, 2019
Found In Version: 8.0.0.22
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

https://nvd.nist.gov/vuln/detail/CVE-2017-15298

CVEs


Live chat
Online