Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 16 of 16 results


CVE-2016-10130

Medium priority
Vulnerable

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

1 affected packages

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libgit2 Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10129

Medium priority
Vulnerable

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

1 affected packages

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libgit2 Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-10128

Medium priority
Vulnerable

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted...

1 affected packages

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libgit2 Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-8569

Low priority

Some fixes available 2 of 5

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

1 affected packages

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libgit2 Not affected Not affected Not affected Fixed
Show less packages

CVE-2016-8568

Medium priority

Some fixes available 2 of 5

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

1 affected packages

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libgit2 Not affected Not affected Not affected Fixed
Show less packages

CVE-2014-9390

Medium priority

Some fixes available 26 of 41

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...

5 affected packages

git, git-core, jgit, libgit2, mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
git Fixed Fixed Fixed Fixed Fixed
git-core Not in release Not in release Not in release Not in release Not in release
jgit Not affected Not affected Not affected Not affected Not affected
libgit2 Not affected Not affected Not affected Not affected Not affected
mercurial Not affected Not affected Not affected Not affected Not affected
Show less packages