CVE-2024-0684

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:coreutils:9.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:9.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:9.4:*:*:*:*:*:*:*

History

14 Feb 2024, 00:26

Type Values Removed Values Added
First Time Gnu coreutils
Gnu
CPE cpe:2.3:a:gnu:coreutils:9.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:9.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:9.2:*:*:*:*:*:*:*
CWE CWE-787
References () https://access.redhat.com/security/cve/CVE-2024-0684 - () https://access.redhat.com/security/cve/CVE-2024-0684 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2258948 - () https://bugzilla.redhat.com/show_bug.cgi?id=2258948 - Issue Tracking, Patch
References () https://www.openwall.com/lists/oss-security/2024/01/18/2 - () https://www.openwall.com/lists/oss-security/2024/01/18/2 - Mailing List, Patch

06 Feb 2024, 13:53

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en el programa "split" de GNU coreutils. Podría producirse un desbordamiento de almacenamiento dinámico con datos controlados por el usuario de varios cientos de bytes de longitud en la función line_bytes_split(), lo que podría provocar un bloqueo de la aplicación y una denegación de servicio.

06 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 09:15

Updated : 2024-02-14 00:26


NVD link : CVE-2024-0684

Mitre link : CVE-2024-0684

CVE.ORG link : CVE-2024-0684


JSON object : View

Products Affected

gnu

  • coreutils
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow