← Vulnerability feed

Vulnerability record · CVE-2008-3546 · published 7 August 2008

CVE-2008-3546: Git memory buffer overflow vulnerability

Git · Git

Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

7.5 CVSS 2.0 High EPSS 4.3% · top 9.2% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kerneltrap.org/mailarchive/git/2008/7/16/2529284 Exploit
http://secunia.com/advisories/31347 Vendor Advisory
http://secunia.com/advisories/31780
http://secunia.com/advisories/32029
http://secunia.com/advisories/32384
http://secunia.com/advisories/33964
http://security.gentoo.org/glsa/glsa-200809-16.xml
http://wiki.rpath.com/Advisories:rPSA-2008-0253
http://www.debian.org/security/2008/dsa-1637
http://www.kernel.org/pub/software/scm/git/docs/RelNotes-1.5.6.4.txt
http://www.securityfocus.com/archive/1/495391/100/0/threaded
http://www.securityfocus.com/bid/30549
http://www.securitytracker.com/id?1020627
http://www.ubuntu.com/usn/USN-723-1
http://www.vupen.com/english/advisories/2008/2306
https://exchange.xforce.ibmcloud.com/vulnerabilities/44217
https://issues.rpath.com/browse/RPL-2707
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00729.html
http://kerneltrap.org/mailarchive/git/2008/7/16/2529284 Exploit
http://secunia.com/advisories/31347 Vendor Advisory
http://secunia.com/advisories/31780
http://secunia.com/advisories/32029
http://secunia.com/advisories/32384
http://secunia.com/advisories/33964
http://security.gentoo.org/glsa/glsa-200809-16.xml
http://wiki.rpath.com/Advisories:rPSA-2008-0253
http://www.debian.org/security/2008/dsa-1637
http://www.kernel.org/pub/software/scm/git/docs/RelNotes-1.5.6.4.txt
http://www.securityfocus.com/archive/1/495391/100/0/threaded
http://www.securityfocus.com/bid/30549
http://www.securitytracker.com/id?1020627
http://www.ubuntu.com/usn/USN-723-1
http://www.vupen.com/english/advisories/2008/2306
https://exchange.xforce.ibmcloud.com/vulnerabilities/44217
https://issues.rpath.com/browse/RPL-2707
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00729.html

Track CVE-2008-3546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-25648Git argument injection vulnerabilityThe package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) fu…EPSS 4.9%9.0CVE-2024-32002Git path traversal vulnerabilityGit is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be c…EPSS 29%7.5CVE-2024-52005Git vulnerabilityGit is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the …EPSS 0.51%7.5CVE-2020-5260Git improper input validation vulnerabilityAffected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…EPSS 10%7.5CVE-2008-5516Git os command injection vulnerabilityThe web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se…EPSS 4.4%7.5CVE-2008-5517Git code injection vulnerabilityThe web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) gi…EPSS 12%7.5CVE-2006-0477Git vulnerabilityBuffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic li…EPSS 3.3%5.0CVE-2009-2108Git vulnerabilitygit-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contai…EPSS 5.8%

Source: NIST National Vulnerability Database (record CVE-2008-3546), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.