Off-by-one error in the convert_query_hexchar function in...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Dec 22, 2023
Description
Published by the National Vulnerability Database
Mar 20, 2011
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Dec 22, 2023
Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.
References