Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch64-4x3c-w3jq

Опубликовано: 27 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

EPSS

Процентиль: 3%
0.00018
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 4.4
ubuntu
3 месяца назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
redhat
3 месяца назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
nvd
3 месяца назад

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

CVSS3: 4.4
debian
3 месяца назад

A flaw was found in GNU Coreutils. The sort utility's begfield() funct ...

suse-cvrf
26 дней назад

Security update for coreutils

EPSS

Процентиль: 3%
0.00018
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-121