CVE-2009-2108

git 1.4.4.5-1.6.3 - Denial of Service via Unrecognized Arguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2108. PoCs published by Shawn O. Pearce.

AI-analyzed exploit summary This exploit leverages a denial-of-service vulnerability in Git by sending a malformed request to the git-upload-pack service, causing the daemon to enter an infinite loop. The PoC uses Perl to craft a malicious packet and sends it via netcat to the target host.

Description

git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shawn O. Pearce · textdoslinux
https://www.exploit-db.com/exploits/33036

This exploit leverages a denial-of-service vulnerability in Git by sending a malformed request to the git-upload-pack service, causing the daemon to enter an infinite loop. The PoC uses Perl to craft a malicious packet and sends it via netcat to the target host.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Git 1.4.4.5 through 1.6.3.2
No auth needed
Prerequisites: Network access to the target Git daemon on port 9418
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022398
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1579
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51083
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55034
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35730
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01126.html
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01056.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35437
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35338
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200907-05.xml
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:155
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01045.html
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/06/12/1

Scores

EPSS 0.1856
EPSS Percentile 95.3%

Details

CWE
CWE-399
Status published
Products (37)
git/git 1.4.4.5
git/git 1.5.0 (4 CPE variants)
git/git 1.5.0.1
git/git 1.5.0.2
git/git 1.5.0.3
git/git 1.5.0.4
git/git 1.5.0.5
git/git 1.5.0.6
git/git 1.5.0.7
git/git 1.5.1
... and 27 more
Published Jun 18, 2009
Tracked Since Feb 18, 2026