← Vulnerability feed

Vulnerability record · CVE-2009-2108 · published 18 June 2009

CVE-2009-2108: Git vulnerability

Git · Git

git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

5.0 CVSS 2.0 Medium EPSS 5.8% · top 7.1% CWE-399 · CWE-399
5.0CVSS 2.0 base score
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://article.gmane.org/gmane.comp.version-control.git/120733 Patch
http://osvdb.org/55034
http://secunia.com/advisories/35437 Vendor Advisory
http://secunia.com/advisories/35730
http://security.gentoo.org/glsa/glsa-200907-05.xml
http://thread.gmane.org/gmane.comp.version-control.git/120724 Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2009:155
http://www.openwall.com/lists/oss-security/2009/06/12/1 Patch
http://www.securityfocus.com/bid/35338
http://www.securitytracker.com/id?1022398
http://www.vupen.com/english/advisories/2009/1579 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/51083
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01045.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01056.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01126.html
https://www.redhat.com/archives/fedora-security-list/2009-June/msg00000.html Patch
http://article.gmane.org/gmane.comp.version-control.git/120733 Patch
http://osvdb.org/55034
http://secunia.com/advisories/35437 Vendor Advisory
http://secunia.com/advisories/35730
http://security.gentoo.org/glsa/glsa-200907-05.xml
http://thread.gmane.org/gmane.comp.version-control.git/120724 Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2009:155
http://www.openwall.com/lists/oss-security/2009/06/12/1 Patch
http://www.securityfocus.com/bid/35338
http://www.securitytracker.com/id?1022398
http://www.vupen.com/english/advisories/2009/1579 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/51083
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01045.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01056.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01126.html
https://www.redhat.com/archives/fedora-security-list/2009-June/msg00000.html Patch

Track CVE-2009-2108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-25648Git argument injection vulnerabilityThe package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) fu…EPSS 4.9%9.0CVE-2024-32002Git path traversal vulnerabilityGit is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be c…EPSS 29%7.5CVE-2024-52005Git vulnerabilityGit is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the …EPSS 0.51%7.5CVE-2020-5260Git improper input validation vulnerabilityAffected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…EPSS 10%7.5CVE-2008-5516Git os command injection vulnerabilityThe web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se…EPSS 4.4%7.5CVE-2008-5517Git code injection vulnerabilityThe web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) gi…EPSS 12%7.5CVE-2008-3546Git memory buffer overflow vulnerabilityStack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrar…EPSS 4.3%7.5CVE-2006-0477Git vulnerabilityBuffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic li…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2009-2108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.