Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-10-14T19:00:00

Updated: 2020-05-01T23:06:14

Reserved: 2017-10-14T00:00:00


Link: CVE-2017-15298

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-10-14T22:29:00.200

Modified: 2020-05-02T00:15:11.623


Link: CVE-2017-15298

JSON object: View

cve-icon Redhat Information

No data.

CWE