Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1345

Опубликовано: 18 янв. 2015
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

A heap-based buffer overflow flaw was found in the way grep processed certain pattern and text combinations. An attacker able to trick a user into running grep on specially crafted input could use this flaw to crash grep or, potentially, read from uninitialized memory.

Отчет

This issue did not affect versions of grep as shipped in Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5grepNot affected
Red Hat Enterprise Linux 6grepFixedRHSA-2015:144720.07.2015
Red Hat Enterprise Linux 7grepFixedRHSA-2015:211119.11.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
Дефект:
CWE-125

EPSS

Процентиль: 26%
0.00088
Низкий

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

nvd
больше 10 лет назад

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

debian
больше 10 лет назад

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows ...

github
больше 3 лет назад

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

oracle-oval
почти 10 лет назад

ELSA-2015-2111: grep security and bug fix update (LOW)

EPSS

Процентиль: 26%
0.00088
Низкий

1.2 Low

CVSS2