Bug 1003810 - (CVE-2016-8568) VUL-0: CVE-2016-8568, CVE-2016-8569: libgit2: invalid memory accesses parsing object files
(CVE-2016-8568)
VUL-0: CVE-2016-8568, CVE-2016-8569: libgit2: invalid memory accesses parsing...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other All
: P3 - Medium : Normal
: unspecified
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-10-08 13:40 UTC by Mikhail Kasimov
Modified: 2019-05-22 00:35 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Kasimov 2016-10-08 13:40:26 UTC
References: http://seclists.org/oss-sec/2016/q4/59

====================================================
Hi,

We recently reported two invalid memory accesses in the last revision
of libgit2:

* Read out-of-bounds in git_oid_nfmt:
https://github.com/libgit2/libgit2/issues/3936

* DoS using a null pointer derreference in git_commit_message:
https://github.com/libgit2/libgit2/issues/3937

The developers are preparing a patch to harden object parsing in libgit2 here:

https://github.com/libgit2/libgit2/pull/3956

Please assign one or more CVE if suitable.

Regards,
Gustavo.
====================================================

https://software.opensuse.org/package/libgit2
Comment 2 Swamp Workflow Management 2016-10-08 22:00:14 UTC
bugbot adjusting priority
Comment 3 Marcus Meissner 2016-10-09 09:17:01 UTC
in sle12 sp2 ga tree and opensuse
Comment 6 Andreas Stieger 2016-12-01 12:48:36 UTC
Scott, please submit for openSUSE:

devel:libraries:c_c++/libgit2 for openSUSE:Factory
openSUSE:13.2:Update/libgit2
openSUSE:Leap:42.1:Update/libgit2
openSUSE:Backports:SLE-12-SP1/libgit2
Comment 7 Swamp Workflow Management 2016-12-02 14:08:47 UTC
SUSE-SU-2016:2969-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1003810
CVE References: CVE-2016-8568,CVE-2016-8569
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libgit2-0.24.1-3.1
Comment 8 Scott Reeves 2016-12-06 22:41:56 UTC
HPJ - can you look into the versions listed in comment#6 and submit patches if necessary (devel:libraries:c_c++ has already been fixed). The code has changed quite a bit for some of the older versions.
Comment 9 Swamp Workflow Management 2016-12-12 18:10:22 UTC
openSUSE-SU-2016:3097-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1003810
CVE References: CVE-2016-8568,CVE-2016-8569
Sources used:
openSUSE Leap 42.2 (src):    libgit2-0.24.1-3.1
Comment 10 Andreas Stieger 2017-01-11 10:16:18 UTC
Ping for the submissions below:

(In reply to Andreas Stieger from comment #6)
> openSUSE:13.2:Update/libgit2

Couple of days left in maintenance for this one.

> openSUSE:Leap:42.1:Update/libgit2

..months

> openSUSE:Backports:SLE-12-SP1/libgit2

https://build.opensuse.org/request/show/449636
Comment 11 Bernhard Wiedemann 2017-01-12 13:00:40 UTC
This is an autogenerated message for OBS integration:
This bug (1003810) was mentioned in
https://build.opensuse.org/request/show/449822 13.2 / libgit2
https://build.opensuse.org/request/show/449835 42.1 / libgit2
Comment 12 Swamp Workflow Management 2017-01-17 18:47:29 UTC
openSUSE-SU-2017:0184-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1003810
CVE References: CVE-2016-8568,CVE-2016-8569
Sources used:
openSUSE 13.2 (src):    libgit2-0.21.5-2.6.1
Comment 13 Swamp Workflow Management 2017-01-18 17:09:10 UTC
openSUSE-SU-2017:0195-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1003810
CVE References: CVE-2016-8568,CVE-2016-8569
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    libgit2-0.24.3-6.1
Comment 14 Scott Reeves 2017-01-18 23:32:12 UTC
All submissions are done - assigning to security team.
Comment 15 Swamp Workflow Management 2017-01-19 17:09:20 UTC
openSUSE-SU-2017:0208-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1003810
CVE References: CVE-2016-8568,CVE-2016-8569
Sources used:
openSUSE Leap 42.1 (src):    libgit2-0.22.1-5.1
Comment 16 Marcus Meissner 2017-02-09 10:45:19 UTC
releaqsewd