Description
A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.
Problem types
Product status
v9.2
v9.3
v9.4
v9.5
Timeline
| 2024-01-18: | Reported to Red Hat. |
| 2024-01-18: | Made public. |
References
access.redhat.com/security/cve/CVE-2024-0684
bugzilla.redhat.com/show_bug.cgi?id=2258948 (RHBZ#2258948)
www.openwall.com/lists/oss-security/2024/01/18/2