SB2015021202 - Out-of-bounds read in GNU grep
Published: February 12, 2015 Updated: July 28, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2015-1345)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary error in the bmexec_trans function in kwset.c. A remote attacker can create crafted input when using the -F option, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.
References
- http://debbugs.gnu.org/cgi/bugreport.cgi?bug=19563
- http://git.savannah.gnu.org/cgit/grep.git/commit/?id=83a95bd8c8561875b948cadd417c653dbe7ef2e2
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00037.html
- http://rhn.redhat.com/errata/RHSA-2015-1447.html
- http://www.openwall.com/lists/oss-security/2015/01/22/10
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/72281