← Back

CVE-2011-1027

nvd nist
Published: Mar 20, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

Affected (26)

1 product
Cgit
1 product
Fedora
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Lars Hjemli
Up to 0.8.3.4
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7
Version 0.8.1.1
Version 0.8.1
Version 0.8.2.1
Version 0.8.2.2
Version 0.8.2
Version 0.8.3.1
Version 0.8.3.2
Version 0.8.3.3
Version 0.8.3
Version 0.8
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 13
Version 14
Version 15

References (26)

Source: secalert@redhat.com
Mailing ListPatchThird Party Advisory
Source: secalert@redhat.com
Broken LinkVendor Advisory
Source: secalert@redhat.com
Broken LinkVendor Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken LinkExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
ExploitIssue TrackingPatch
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.