
oss-sec mailing list archives
Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished cve-2016-2324 and cve-2016-2315)
From: Solar Designer <solar () openwall com>
Date: Tue, 15 Mar 2016 18:43:07 +0300
Thanks for bringing this to oss-security. On Tue, Mar 15, 2016 at 03:55:37PM +0100, La??l Cellier wrote:
Hello, original report describing the overflow is here http://pastebin.com/UX2P2jjg
Going forward, please post the actual content directly to oss-security, not (only) via reference. I've attached the contents of this pastebin to this message, so that it's properly archived. (No idea why you had "cve" obfuscated with Unicode, but I undid that.) Alexander
Attachment:
cve-2016-2315.c
Description:
Current thread:
- server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 15)
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished cve-2016-2324 and cve-2016-2315) Solar Designer (Mar 15)
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Tyler Hicks (Mar 15)
- Message not available
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 15)
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 15)
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 15)
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 15)
- <Possible follow-ups>
- Re: server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished ᴄᴠᴇ-2016-2324 and ᴄᴠᴇ‑2016‑2315) Laël Cellier (Mar 16)