CVE-2016-10130
24.03.2017, 15:59
The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libgit2_project | libgit2 | 𝑥 ≤ 0.24.5 |
| libgit2_project | libgit2 | 0.25.0 |
| libgit2_project | libgit2 | 0.25.0:rc1 |
| libgit2_project | libgit2 | 0.25.0:rc2 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cargo |
| ||||||||||||||
| libgit2 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libgit2 |
|
Common Weakness Enumeration
References