CVE-2024-0684 Information

Description

A flaw was found in the GNU coreutils \split\ program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function potentially leading to an application crash and denial of service.

Reference

https://access.redhat.com/security/cve/CVE-2024-0684 https://bugzilla.redhat.com/show_bug.cgi?id=2258948 https://www.openwall.com/lists/oss-security/2024/01/18/2

Share on: