Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0911

Опубликовано: 23 янв. 2024
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

Отчет

The indent program is not distributed in Red Hat Enterprise Linux 8 and 9. Therefore, these Red Hat Enterprise Linux versions are not affected.

Меры по смягчению последствий

Do not process untrusted files with the indent program.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6indentOut of support scope
Red Hat Enterprise Linux 7indentOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2260399indent: heap-based buffer overflow in set_buf_break()

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

CVSS3: 5.5
nvd
около 2 лет назад

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

CVSS3: 5.5
debian
около 2 лет назад

A flaw was found in indent, a program for formatting C code. This issu ...

suse-cvrf
почти 2 года назад

Security update for indent

suse-cvrf
почти 2 года назад

Security update for indent

5.5 Medium

CVSS3