CVE Database
/

CVE-2011-1027

Back to search

CVE-2011-1027

Published: Mar 20, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2011-2803
vendor-advisory
x_refsource_FEDORA
71005
vdb-entry
x_refsource_OSVDB
FEDORA-2011-2790
vendor-advisory
x_refsource_FEDORA
46756
vdb-entry
x_refsource_BID
ADV-2011-0667
vdb-entry
x_refsource_VUPEN
43788
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-2815
vendor-advisory
x_refsource_FEDORA
43633
third-party-advisory
x_refsource_SECUNIA
[git] 20110305 [ANNOUNCE] CGIT 0.8.3.5
mailing-list
x_refsource_MLIST

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now