Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0911

Опубликовано: 23 янв. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

Отчет

The indent program is not distributed in Red Hat Enterprise Linux 8 and 9. Therefore, these Red Hat Enterprise Linux versions are not affected.

Меры по смягчению последствий

Do not process untrusted files with the indent program.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6indentOut of support scope
Red Hat Enterprise Linux 7indentOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2260399indent: heap-based buffer overflow in set_buf_break()

EPSS

Процентиль: 23%
0.00312
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

CVSS3: 5.5
nvd
больше 2 лет назад

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

CVSS3: 5.5
debian
больше 2 лет назад

A flaw was found in indent, a program for formatting C code. This issu ...

suse-cvrf
больше 2 лет назад

Security update for indent

suse-cvrf
больше 2 лет назад

Security update for indent

EPSS

Процентиль: 23%
0.00312
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2024-0911