« List of all CVEs

CVE-2024-0684

Coreutils: heap overflow in split --line-bytes with very long lines

Published: 2/6/2024 Last updated: 8/8/2024 Reserved: 1/18/2024

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

CNA assigner: fedora (92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.5 Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (5)

conf-timeout fstar karamel kremlin liquidsoap

Products affected (1)

Product Vendor Version
23.0 ap375646

References (7)