CVE-2018-8099 PUBLISHED

Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.

EPSS 1.18% · 78.6th percentile

Risk Scores

EPSS Score
1.18%
78.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlibgit20.19.0-2ubuntu0.4+esm1, 0.19.0-2ubuntu0.4, 0.19.0-2
Ubuntu:Pro:18.04:LTSlibgit20.26.0+dfsg.1-1.1ubuntu0.2, 0.26.0+dfsg.1-1.1ubuntu0.2+esm1, 0
Ubuntu:Pro:16.04:LTSlibgit20.24.1-2ubuntu0.2, 0.24.1-2ubuntu0.2+esm1, 0.24.1-2ubuntu0.2+esm2

Timeline

References

Open in Interactive Console →