Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9488

Опубликовано: 10 мар. 2015
Источник: redhat
CVSS3: 2.5
CVSS2: 1.2

Описание

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.

An out of bound read, with a maximum of 5 bytes, was found in the way the is_utf8_well_formed() function parsed UTF-8 characters. If less was to be recompiled with an address sanitizer, a specially crafted input could crash less.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5lessWill not fix
Red Hat Enterprise Linux 6lessWill not fix
Red Hat Enterprise Linux 7lessWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1201309less: out of bounds read access in is_utf8_well_formed()

2.5 Low

CVSS3

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.

nvd
почти 11 лет назад

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.

debian
почти 11 лет назад

The is_utf8_well_formed function in GNU less before 475 allows remote ...

suse-cvrf
больше 5 лет назад

Security update for less

github
больше 3 лет назад

The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.

2.5 Low

CVSS3

1.2 Low

CVSS2