CVE-2016-2315
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 17%
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
Affected products
n/a · n/aReferences
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183147.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/179121.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/180763.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00061.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00071.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00077.htmlhttp://lists.opensuse.org/opensuse-updates/2016-04/msg00011.html