Bugzilla – Bug 1019036
VUL-0: CVE-2016-10128,CVE-2016-10129: libgit2: edge cases in the Git Smart Protocol can lead to attempting to parse outside of the buffer
Last modified: 2019-05-22 00:38:48 UTC
https://github.com/libgit2/libgit2/releases/tag/v0.25.1 https://github.com/libgit2/libgit2/releases/tag/v0.24.6 [...] performs extra sanitization for some edge cases in the Git Smart Protocol which can lead to attempting to parse outside of the buffer. https://github.com/libgit2/libgit2/commit/66e3774d279672ee51c3b54545a79d20d1ada834 https://github.com/libgit2/libgit2/commit/2fdef641fd0dd2828bd948234ae86de75221a11a merge: https://github.com/libgit2/libgit2/commit/6850b516b9bb7de6d8e7e1f8355acf05a7a91d98
bugbot adjusting priority
https://github.com/libgit2/libgit2/commit/66e3774d279672ee51c3b54545a79d20d1ada834 Use CVE-2016-10128. https://github.com/libgit2/libgit2/commit/2fdef641fd0dd2828bd948234ae86de75221a11a Use CVE-2016-10129.
HPJ are these for you?
For openSUSE, requesting fixes for: openSUSE:13.2:Update/libgit2 (*couple of days left on maintenance) openSUSE:Leap:42.1:Update/libgit2 openSUSE:Backports:SLE-12-SP1/libgit2 (just submit 0.24.6 from devel:libraries:c_c++ once https://build.opensuse.org/request/show/449627 does through) Please include bug 1003810. Rest is done via SLE maintenance.
SLE12-SP2 - IBS SR#127382 Leap 42.1 - OBS SR#453542 openSUSE:Backports:SLE-12-SP1 - OBS SR#453540 Leap42.2 will populate from SLE12 submission and 13.2 is out of support and not returned by a mbranch checkout. Assigning back to security team...
This is an autogenerated message for OBS integration: This bug (1019036) was mentioned in https://build.opensuse.org/request/show/453540 Backports:SLE-12-SP1 / libgit2 https://build.opensuse.org/request/show/453542 42.1 / libgit2
openSUSE-SU-2017:0397-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1019036,1019037 CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339 Sources used: openSUSE Leap 42.1 (src): libgit2-0.22.1-8.1
openSUSE-SU-2017:0405-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1019036,1019037 CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): libgit2-0.24.6-10.1
released
SUSE-SU-2017:0433-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1019036,1019037 CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libgit2-0.24.1-6.1
openSUSE-SU-2017:0484-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1019036,1019037 CVE References: CVE-2016-10128,CVE-2016-10129,CVE-2016-10130,CVE-2017-5338,CVE-2017-5339 Sources used: openSUSE Leap 42.2 (src): libgit2-0.24.1-6.1