Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4041

Опубликовано: 24 янв. 2020
Источник: debian
EPSS Низкий

Описание

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
coreutilsnot-affectedpackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=928749

  • https://github.com/pixelb/coreutils/commit/bea5e36cc876ed627bb5e0eca36fdfaa6465e940

  • http://pkgs.fedoraproject.org/cgit/coreutils.git/plain/coreutils-i18n.patch

EPSS

Процентиль: 21%
0.00066
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

redhat
почти 11 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

CVSS3: 7.8
nvd
около 6 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

CVSS3: 7.8
github
больше 3 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

suse-cvrf
больше 10 лет назад

Security update for coreutils

EPSS

Процентиль: 21%
0.00066
Низкий