CVE-2018-8098: Integer Overflow
Integer overflow in the index.c:readentry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in v0.26.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2018-8098.
What is the severity of CVE-2018-8098?
The severity of CVE-2018-8098 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2018-8098?
Versions of libgit2 before v0.26.2 and Debian Linux version 9.0 are affected by CVE-2018-8098.
What is the impact of CVE-2018-8098?
CVE-2018-8098 can cause a denial of service (out-of-bounds read) due to an integer overflow in the index.c:read_entry() function.
How can I fix CVE-2018-8098?
To fix CVE-2018-8098, update libgit2 to version 0.26.2 or later.