CVE-2018-15501: Out-of-bounds Read
(updated )
There is a vulnerability in ng_pkt
(transports/smart_pkt.c
) in libgit2 which is wrapped by the rugged gem. A remote attacker can send a crafted smart-protocol ng
packet that lacks a \0
byte to trigger an out-of-bounds read that leads to DoS.
References
Detect and mitigate CVE-2018-15501 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →