Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0684

Опубликовано: 18 янв. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

Отчет

This flaw is only present in coreutils 9.2, 9.3 and 9.4. Red Hat Enterprise Linux is not affected by this CVE as it ships an older version of coreutils that does not include the affected code.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6coreutilsNot affected
Red Hat Enterprise Linux 7coreutilsNot affected
Red Hat Enterprise Linux 8coreutilsNot affected
Red Hat Enterprise Linux 9coreutilsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2258948coreutils: heap overflow in split --line-bytes with very long lines

EPSS

Процентиль: 22%
0.00071
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 1 года назад

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

CVSS3: 5.5
nvd
больше 1 года назад

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

CVSS3: 5.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
больше 1 года назад

A flaw was found in the GNU coreutils "split" program. A heap overflow ...

CVSS3: 5.5
github
больше 1 года назад

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

EPSS

Процентиль: 22%
0.00071
Низкий

5.5 Medium

CVSS3