DEBIAN-CVE-2023-49568
Dashboard / Vulnerabilities / DEBIAN-CVE-2023-49568
Summary:
Details: A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory filesystem supported by go-git are not affected by this vulnerability. This is a go-git implementation issue and does not affect the upstream git cli.
Affected packages
Package
Name: golang-github-go-git-go-git
Purl: pkg:deb/debian/golang-github-go-git-go-git?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
5.11.0-1
5.11.0-2
5.11.0-3
5.11.0-4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
