// For flags

CVE-2012-5667

Grep < 2.11 - Integer Overflow Crash (PoC)

Severity Score

4.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

Múltiples desbordamientos de enteros en GNU Grep antes de v2.11 podría permitir a atacantes locales o remotos ejecutar código arbitrario a través de vectores relacionados con una larga línea de entrada que dispara un desbordamiento de búfer basado en memoria dinámica.

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way grep parsed large lines of data. An attacker able to trick a user into running grep on a specially crafted data file could use this flaw to crash grep or, potentially, execute arbitrary code with the privileges of the user running grep.

Grep versions prior to 2.11 suffer from an integer overflow vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-10-24 CVE Reserved
  • 2012-12-31 CVE Published
  • 2012-12-31 First Exploit
  • 2024-08-03 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-122: Heap-based Buffer Overflow
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
<= 2.10
Search vendor "Gnu" for product "Grep" and version " <= 2.10"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.2
Search vendor "Gnu" for product "Grep" and version "2.2"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.3
Search vendor "Gnu" for product "Grep" and version "2.3"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.4
Search vendor "Gnu" for product "Grep" and version "2.4"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.4.1
Search vendor "Gnu" for product "Grep" and version "2.4.1"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.4.2
Search vendor "Gnu" for product "Grep" and version "2.4.2"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.5
Search vendor "Gnu" for product "Grep" and version "2.5"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.5.1
Search vendor "Gnu" for product "Grep" and version "2.5.1"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.5.1
Search vendor "Gnu" for product "Grep" and version "2.5.1"
a
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.5.3
Search vendor "Gnu" for product "Grep" and version "2.5.3"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.5.4
Search vendor "Gnu" for product "Grep" and version "2.5.4"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.6
Search vendor "Gnu" for product "Grep" and version "2.6"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.6.1
Search vendor "Gnu" for product "Grep" and version "2.6.1"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.6.2
Search vendor "Gnu" for product "Grep" and version "2.6.2"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.6.3
Search vendor "Gnu" for product "Grep" and version "2.6.3"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.7
Search vendor "Gnu" for product "Grep" and version "2.7"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.8
Search vendor "Gnu" for product "Grep" and version "2.8"
-
Affected
Gnu
Search vendor "Gnu"
Grep
Search vendor "Gnu" for product "Grep"
2.9
Search vendor "Gnu" for product "Grep" and version "2.9"
-
Affected