CVE-2024-0684
Coreutils: heap overflow in split --line-bytes with very long lines
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.
Se encontró una falla en el programa "split" de GNU coreutils. Podría producirse un desbordamiento de almacenamiento dinámico con datos controlados por el usuario de varios cientos de bytes de longitud en la función line_bytes_split(), lo que podría provocar un bloqueo de la aplicación y una denegación de servicio.
A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly arbitrary code execution. Versions greater than or equal to 9.4-r1 are affected.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-18 CVE Reserved
- 2024-01-20 First Exploit
- 2024-02-06 CVE Published
- 2024-08-08 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-0684 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/Valentin-Metz/writeup_split | 2024-01-20 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2258948 | 2024-02-14 | |
https://www.openwall.com/lists/oss-security/2024/01/18/2 | 2024-02-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Coreutils Search vendor "Gnu" for product "Coreutils" | 9.2 Search vendor "Gnu" for product "Coreutils" and version "9.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Coreutils Search vendor "Gnu" for product "Coreutils" | 9.3 Search vendor "Gnu" for product "Coreutils" and version "9.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Coreutils Search vendor "Gnu" for product "Coreutils" | 9.4 Search vendor "Gnu" for product "Coreutils" and version "9.4" | - |
Affected
|