The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 25 | 25.x |
| fedoraproject / fedora | 24 | 24.x |
| fedoraproject / fedora | 23 | 23.x |
| suse / linux_enterprise | 12.0 | 12.0.x |
| opensuse / leap | 42.2 | 42.2.x |
| opensuse / leap | 42.1 | 42.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| libgit2_project / libgit2 | - | 0.24.2.x |