CVE-2024-0911

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:indent:2.2.13:*:*:*:*:*:*:*

History

14 Feb 2024, 18:15

Type Values Removed Values Added
References
  • () https://lists.gnu.org/archive/html/bug-indent/2024-01/msg00000.html -
Summary (en) A flaw was found in Indent. This issue may allow a local user to use a specially-crafted file to trigger a heap-based buffer overflow, which can lead to an application crash. (en) A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

14 Feb 2024, 00:27

Type Values Removed Values Added
First Time Gnu indent
Gnu
CWE CWE-787
References () https://access.redhat.com/security/cve/CVE-2024-0911 - () https://access.redhat.com/security/cve/CVE-2024-0911 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2260399 - () https://bugzilla.redhat.com/show_bug.cgi?id=2260399 - Issue Tracking
CPE cpe:2.3:a:gnu:indent:2.2.13:*:*:*:*:*:*:*
Summary
  • (es) Se encontró una falla en Indent. Este problema puede permitir que un usuario local utilice un archivo especialmente manipulado para desencadenar un desbordamiento de búfer de almacenamiento dinámico, lo que puede provocar un bloqueo de la aplicación.

06 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 15:15

Updated : 2024-02-14 18:15


NVD link : CVE-2024-0911

Mitre link : CVE-2024-0911

CVE.ORG link : CVE-2024-0911


JSON object : View

Products Affected

gnu

  • indent
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow