Upstream information

CVE-2008-3546 at MITRE

Description

Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.5
Vector AV:N/AC:L/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 415345 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.0
  • git-debuginfo >= 1.5.6-43.1
  • git-debugsource >= 1.5.6-43.1
openSUSE 11.0
  • git >= 1.5.6-43.1
  • git-arch >= 1.5.6-43.1
  • git-core >= 1.5.6-43.1
  • git-cvs >= 1.5.6-43.1
  • git-email >= 1.5.6-43.1
  • git-svn >= 1.5.6-43.1
  • gitk >= 1.5.6-43.1