FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2016-1901

This CVE name corresponds to:

Entered Topic
2016-01-20 cgit -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2016-1901
Phase Assigned(20160114)

Description

Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.

References

Source Reference
MLIST [CGit] 20160114 [ANNOUNCE] CGIT v0.12 Released
MLIST [oss-security] 20160114 CVE Request: CGit - Multiple vulnerabilities
MLIST [oss-security] 20160114 Re: CVE Request: CGit - Multiple vulnerabilities
CONFIRM http://git.zx2c4.com/cgit/commit/?id=4458abf64172a62b92810c2293450106e6dfc763
FEDORA FEDORA-2016-215b507409