CVE-2012-5667
Grep < 2.11 - Integer Overflow Crash (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.
Múltiples desbordamientos de enteros en GNU Grep antes de v2.11 podría permitir a atacantes locales o remotos ejecutar código arbitrario a través de vectores relacionados con una larga línea de entrada que dispara un desbordamiento de búfer basado en memoria dinámica.
An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way grep parsed large lines of data. An attacker able to trick a user into running grep on a specially crafted data file could use this flaw to crash grep or, potentially, execute arbitrary code with the privileges of the user running grep.
Grep versions prior to 2.11 suffer from an integer overflow vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2012-12-31 CVE Published
- 2012-12-31 First Exploit
- 2024-08-03 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-189: Numeric Errors
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://git.sv.gnu.org/gitweb/?p=grep.git%3Ba=shortlog%3Bh=v2.11 | X_refsource_confirm | |
http://lists.gnu.org/archive/html/bug-grep/2012-12/msg00004.html | Mailing List | |
http://openwall.com/lists/oss-security/2012/12/22/6 | Mailing List | |
http://www.securityfocus.com/bid/57033 | Vdb Entry | |
https://bugs.launchpad.net/ubuntu/+source/grep/+bug/1091473 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/23779 | 2012-12-31 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-1447.html | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=889935 | 2015-07-20 | |
https://access.redhat.com/security/cve/CVE-2012-5667 | 2015-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | <= 2.10 Search vendor "Gnu" for product "Grep" and version " <= 2.10" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.2 Search vendor "Gnu" for product "Grep" and version "2.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.3 Search vendor "Gnu" for product "Grep" and version "2.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.4 Search vendor "Gnu" for product "Grep" and version "2.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.4.1 Search vendor "Gnu" for product "Grep" and version "2.4.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.4.2 Search vendor "Gnu" for product "Grep" and version "2.4.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.5 Search vendor "Gnu" for product "Grep" and version "2.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.5.1 Search vendor "Gnu" for product "Grep" and version "2.5.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.5.1 Search vendor "Gnu" for product "Grep" and version "2.5.1" | a |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.5.3 Search vendor "Gnu" for product "Grep" and version "2.5.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.5.4 Search vendor "Gnu" for product "Grep" and version "2.5.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.6 Search vendor "Gnu" for product "Grep" and version "2.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.6.1 Search vendor "Gnu" for product "Grep" and version "2.6.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.6.2 Search vendor "Gnu" for product "Grep" and version "2.6.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.6.3 Search vendor "Gnu" for product "Grep" and version "2.6.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.7 Search vendor "Gnu" for product "Grep" and version "2.7" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.8 Search vendor "Gnu" for product "Grep" and version "2.8" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Grep Search vendor "Gnu" for product "Grep" | 2.9 Search vendor "Gnu" for product "Grep" and version "2.9" | - |
Affected
|