CVE-2018-8098 PUBLISHED

Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.

EPSS 0.74% · 72.8th percentile

Risk Scores

EPSS Score
0.74%
72.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibgit20.24.1-2, 0.24.1-2ubuntu0.2+esm2, 0.24.1-2ubuntu0.2+esm1
Ubuntu:Pro:18.04:LTSlibgit20.26.0+dfsg.1-1.1ubuntu0.2+esm1, 0.25.1+really0.24.6-1, 0.26.0+dfsg.1-1.1
Ubuntu:Pro:14.04:LTSlibgit20.19.0-2ubuntu0.4+esm1, 0.19.0-2ubuntu0.4, 0.19.0-2

Timeline

References

Open in Interactive Console →