Vulnerability Name:

CVE-2018-15501 (CCN-148575)

Assigned:2018-08-17
Published:2018-08-17
Updated:2022-05-11
Summary:In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-15501

Source: MISC
Type: Exploit, Issue Tracking, Patch, Third Party Advisory
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9406

Source: CCN
Type: Bugzilla – Bug 1104641
(CVE-2018-15501) VUL-0: CVE-2018-15471: libgit2: out-of-bounds reads when processing smart-protocol "ng" packets

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1104641

Source: XF
Type: UNKNOWN
libgit2-cve201815501-dos(148575)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/libgit2/libgit2/commit/1f9a8510e1d2f20ed7334eeeddb92c4dd8e7c649

Source: MISC
Type: Release Notes, Third Party Advisory
https://github.com/libgit2/libgit2/releases/tag/v0.26.6

Source: MISC
Type: Release Notes, Third Party Advisory
https://github.com/libgit2/libgit2/releases/tag/v0.27.4

Source: CCN
Type: libgit2 Web site
libgit2

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180825 [SECURITY] [DLA 1477-1] libgit2 security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20220321 [SECURITY] [DLA 2936-1] libgit2 security update

Source: MISC
Type: Third Party Advisory
https://www.pro-linux.de/sicherheit/2/44650/denial-of-service-in-libgit2.html

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-15501

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:libgit2:libgit2:*:*:*:*:*:*:*:* (Version < 0.26.6)
  • OR cpe:/a:libgit2:libgit2:*:*:*:*:*:*:*:* (Version >= 0.27.0 and < 0.27.4)

  • Configuration CCN 1:
  • cpe:/a:libgit2:libgit2:0.26.5:*:*:*:*:*:*:*
  • OR cpe:/a:libgit2:libgit2:0.27.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201815501
    V
    CVE-2018-15501
    2022-09-02
    oval:org.opensuse.security:def:2936
    P
    gmp-devel-6.1.2-4.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2926
    P
    gc-devel-7.6.4-1.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:10444
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:10174
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:10351
    P
    Security update for python-Pygments (Important)
    2021-10-20
    oval:org.opensuse.security:def:10155
    P
    Security update for ffmpeg (Important)
    2021-09-23
    oval:org.opensuse.security:def:10338
    P
    Security update for java-11-openjdk (Important)
    2021-09-03
    oval:org.opensuse.security:def:10329
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:10325
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:10140
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:10321
    P
    Security update for libass (Important)
    2021-08-20
    oval:org.opensuse.security:def:10316
    P
    Security update for webkit2gtk3 (Important)
    2021-08-17
    oval:org.opensuse.security:def:2281
    P
    rmt-server-2.6.8-1.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2255
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2288
    P
    squid-4.13-5.23.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2242
    P
    grub2-x86_64-xen-2.04-20.4 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2286
    P
    sca-patterns-sle15-1.0.1-12.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2275
    P
    python3-Twisted-19.10.0-3.2.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2246
    P
    libapr-util1-dbd-mysql-1.6.1-16.43 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2230
    P
    apache2-mod_wsgi-python3-4.5.18-2.27 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:10274
    P
    Security update for the Linux Kernel (Important)
    2021-06-09
    oval:org.opensuse.security:def:48729
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11280
    P
    cups-filters-1.0.58-2.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10093
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48747
    P
    libtag1-32bit-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124517
    P
    libgit2-24-0.24.1-7.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11302
    P
    ft2demos-2.5.3-2.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16511
    P
    libgit2-24-0.24.1-7.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48728
    P
    kernel-default-extra-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48873
    P
    libtag1-32bit-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10642
    P
    Security update for MozillaThunderbird (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:10249
    P
    Security update for ceph (Important)
    2021-05-04
    oval:org.opensuse.security:def:10397
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:2215
    P
    spice-gtk-devel-0.37-1.92 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:3980
    P
    libgit2-24-0.24.1-7.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2211
    P
    rsyslog-module-gssapi-8.39.0-2.90 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2220
    P
    virt-install-2.2.1-8.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16816
    P
    libgit2-24-0.24.1-7.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:10025
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:10553
    P
    libtidy-0_99-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49316
    P
    python3-python3-saml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17660
    P
    Recommended update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49960
    P
    libshibsp-lite7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17476
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:10998
    P
    libgit2-24 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10459
    P
    krb5-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49076
    P
    cups-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17518
    P
    Security update for MozillaFirefox and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:49797
    P
    pam-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17837
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51371
    P
    Security update for libgit2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:18598
    P
    Security update for qpdf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10620
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10578
    P
    openexr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49473
    P
    libvdpau-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17691
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:50033
    P
    sblim-sfcb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10629
    P
    augeas-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10017
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10478
    P
    libXv-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49220
    P
    libpq5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17603
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17926
    P
    Security update for ntp (Important)
    2020-12-01
    oval:org.opensuse.security:def:10047
    P
    cyrus-sasl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17869
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:18624
    P
    Security update for libgit2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10976
    P
    libapr-util1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17938
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:49864
    P
    python3-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17484
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:49707
    P
    open-vm-tools-desktop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17727
    P
    Security update for subversion (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51309
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:17960
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49929
    P
    python2-salt on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:2018155010000000
    V
    CVE-2018-15501 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-08-18
    oval:com.ubuntu.disco:def:2018155010000000
    V
    CVE-2018-15501 on Ubuntu 19.04 (disco) - medium.
    2018-08-18
    oval:com.ubuntu.bionic:def:2018155010000000
    V
    CVE-2018-15501 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-08-18
    oval:com.ubuntu.bionic:def:201815501000
    V
    CVE-2018-15501 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-08-17
    oval:com.ubuntu.cosmic:def:201815501000
    V
    CVE-2018-15501 on Ubuntu 18.10 (cosmic) - medium.
    2018-08-17
    oval:com.ubuntu.cosmic:def:2018155010000000
    V
    CVE-2018-15501 on Ubuntu 18.10 (cosmic) - medium.
    2018-08-17
    oval:com.ubuntu.trusty:def:201815501000
    V
    CVE-2018-15501 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-08-17
    oval:com.ubuntu.xenial:def:201815501000
    V
    CVE-2018-15501 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-08-17
    BACK
    debian debian linux 8.0
    debian debian linux 9.0
    libgit2 libgit2 *
    libgit2 libgit2 *
    libgit2 libgit2 0.26.5
    libgit2 libgit2 0.27.3