Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4156

Опубликовано: 19 июн. 2023
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

Отчет

This issue is classified with a low severity primarily because this out-of-bounds read is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with gawk. Additionally, the loss of confidentiality is limited and does not represent the real impact of this flaw. Furthermore, gawk does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gawkOut of support scope
Red Hat Enterprise Linux 7gawkFix deferred
Red Hat Enterprise Linux 8gawkFix deferred
Red Hat Enterprise Linux 9gawkFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2215930gawk: heap out of bound read in builtin.c

EPSS

Процентиль: 5%
0.00024
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 1 года назад

A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

CVSS3: 4.4
nvd
больше 1 года назад

A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.

CVSS3: 4.4
debian
больше 1 года назад

A heap out-of-bounds read flaw was found in builtin.c in the gawk pack ...

suse-cvrf
почти 2 года назад

Security update for gawk

suse-cvrf
почти 2 года назад

Security update for gawk

EPSS

Процентиль: 5%
0.00024
Низкий

6.1 Medium

CVSS3