CVE-2018-10887
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory addresses or cause a Denial of Service.
- libgit2
- < 0.27.3
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 2.1% (79th percentile)
- Weakness
- CWE-681, CWE-194, CWE-190, CWE-125
- NVD status
- Modified
- Published
- 2018-07-10
CVE-2018-10887 at NVD
No indexed exploits for CVE-2018-10887 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-10887 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.