CVE-2008-3546
Description
Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the systems PATH_MAX when running GIT utilities such as git-diff or git-grep.
Risk Information
Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.761
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update to GIT git-1.5.6.4 | Windows |
| Update to Slackware git-1.6.1.3-i486-1.tgz | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.0.tgz | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.1.tgz | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.2.tgz | Windows |
| Update to GIT git-1.5.6.4 (x64) | Windows |
| Update to Slackware git-1.6.1.3-i486-1.tgz (x64) | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.0.tgz (x64) | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.1.tgz (x64) | Windows |
| Update to Slackware git-1.6.1.3-i486-1_slack12.2.tgz (x64) | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.5.3 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.5.3-r1 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.5.4 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.6.1 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.6.2 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git (X64) 1.5.6.3 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.5.3 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.5.3-r1 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.5.4 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.6.1 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.6.2 | Windows |
| Vulnerabilities CVE-2008-3546,CVE-2008-5916,CVE-2009-2108,CVE-2010-3906 are affected in Git 1.5.6.3 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-342449 | Git (2.47.0.2) |
| PATCH-342449 | Git (2.47.0.2) |
| PATCH-342449 | Git (2.47.0.2) |
| PATCH-342449 | Git (2.47.0.2) |
| PATCH-342449 | Git (2.47.0.2) |
| PATCH-319947 | Git (x64) (2.32.0) |
| PATCH-319947 | Git (x64) (2.32.0) |
| PATCH-319947 | Git (x64) (2.32.0) |
| PATCH-319947 | Git (x64) (2.32.0) |
| PATCH-319947 | Git (x64) (2.32.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334441 | Git (x64) (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
| PATCH-334440 | Git (2.43.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234