ubuntu · CVE-2008-3546

Quick triage

Priority: low Published: 2008-08-07 21:41:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2008-3546 low priority: Ubuntu including 1 source packages (git-core), 6 status rows across 6 suites (dapper, feisty, gutsy, hardy, intrepid, upstream): released 5, ignored 1.

Description:

Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

cvelogic Threat Intelligence