VDB
CVE-2009-2108
CVE-2009-2108
PUBLISHED
CVSS 5 MEDIUM
git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.
EPSS 18.56% · 95.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
18.56%
95.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| git | git | 1.4.4.5, 1.5.0, 1.5.0 |
Timeline
- May 5, 2009 PoC Published
- Jun 18, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- ADV-2009-1579 vdb
- 1022398 vdb
- gitdaemon-xinetd-dos(51083) vdb
- http://thread.gmane.org/gmane.comp.version-control.git/120724 url
- [fedora-security-list] 20090612 git daemon DoS mailing-list
- 55034 vdb
- 35730 third-party-advisory
- FEDORA-2009-6839 vendor-advisory
- FEDORA-2009-6936 vendor-advisory
- 35437 third-party-advisory
- 35338 vdb
- GLSA-200907-05 vendor-advisory
- MDVSA-2009:155 vendor-advisory
- FEDORA-2009-6809 vendor-advisory
- http://article.gmane.org/gmane.comp.version-control.git/120733 url
- [oss-security] 20090612 Git daemon infinite loop mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2009-2108 advisory