CVE-2012-4465

medium
Published 2012-10-10 · Modified 2026-04-29
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4465

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50734

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
lars_hjemlicgit{"endIncluding":"0.9.0.3"}
lars_hjemlicgit0.1
lars_hjemlicgit0.2
lars_hjemlicgit0.3
lars_hjemlicgit0.4
lars_hjemlicgit0.5
lars_hjemlicgit0.6
lars_hjemlicgit0.6.1
lars_hjemlicgit0.6.2
lars_hjemlicgit0.6.3
lars_hjemlicgit0.7
lars_hjemlicgit0.7.1
lars_hjemlicgit0.7.2
lars_hjemlicgit0.8
lars_hjemlicgit0.8.1
lars_hjemlicgit0.8.1.1
lars_hjemlicgit0.8.2
lars_hjemlicgit0.8.2.1
lars_hjemlicgit0.8.2.2
lars_hjemlicgit0.8.3
lars_hjemlicgit0.8.3.1
lars_hjemlicgit0.8.3.2
lars_hjemlicgit0.8.3.3
lars_hjemlicgit0.8.3.4
lars_hjemlicgit0.8.3.5
lars_hjemlicgit0.9
lars_hjemlicgit0.9.0.1
lars_hjemlicgit0.9.0.2

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.