← Back

CVE-2012-4465

nvd nist
Published: Oct 10, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.

Affected (28)

Products: Lars Hjemli: Cgit
1 product
Cgit
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Lars Hjemli
Up to 0.9.0.3
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7
Version 0.8.1.1
Version 0.8.1
Version 0.8.2.1
Version 0.8.2.2
Version 0.8.2
Version 0.8.3.1
Version 0.8.3.2
Version 0.8.3.3
Version 0.8.3.4
Version 0.8.3.5
Version 0.8.3
Version 0.8
Version 0.9.0.1
Version 0.9.0.2
Version 0.9

References (14)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.