Wind River Support Network

HomeDefectsLIN9-5551
Fixed

LIN9-5551 : Security Advisory - git - CVE-2017-15298

Created: Oct 16, 2017    Updated: May 18, 2019
Resolved Date: Apr 19, 2019
Found In Version: 9.0.0.11
Fix Version: 9.0.0.21
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

https://nvd.nist.gov/vuln/detail/CVE-2017-15298

CVEs


Live chat
Online