Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4041

Опубликовано: 27 апр. 2015
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

Меры по смягчению последствий

This flaw is triggered by using sort on specially crafted malicious data file. When using sort with trusted inputs, this flaw cannot be triggered.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5coreutilsNot affected
Red Hat Enterprise Linux 6coreutilsAffected
Red Hat Enterprise Linux 7coreutilsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1223813coreutils: heap buffer overflow in sort(1) keycompare_mb()

EPSS

Процентиль: 21%
0.00066
Низкий

3.7 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

CVSS3: 7.8
nvd
около 6 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

CVSS3: 7.8
debian
около 6 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through ...

CVSS3: 7.8
github
больше 3 лет назад

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

suse-cvrf
больше 10 лет назад

Security update for coreutils

EPSS

Процентиль: 21%
0.00066
Низкий

3.7 Low

CVSS2