Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1901.json"
[
{
"source": "https://git.zx2c4.com/cgit@4458abf64172a62b92810c2293450106e6dfc763",
"digest": {
"length": 502.0,
"function_hash": "91807045455295017519516621474102082140"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "cgit.c",
"function": "authenticate_post"
},
"id": "CVE-2016-1901-95834c7c"
},
{
"source": "https://git.zx2c4.com/cgit@4458abf64172a62b92810c2293450106e6dfc763",
"digest": {
"line_hashes": [
"50161904421011037412943174156570592313",
"323348394024932948650418271075221821184",
"134652070258692373190625334827825705051",
"141316581865117512757489622978323703720"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "cgit.c"
},
"id": "CVE-2016-1901-d5b187a7"
}
]