CVE: CVE-2011-1027

Export to Word

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

Threat-Mapped Scoring

Score: 1.9

Priority: P3 - Important (Medium)

EPSS

Score: 0.05194
Percentile: 0.89477

CVSS Scoring

CVSS v2 Score: 5.0

Severity:

Mapped CWE(s)

Affected Products

← Back to Home