CVE-2024-53849
Several stack buffer overflows and pointer overflows in editorconfig-core-c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains many escaped characters. The added backslashes leave too little space in the output pattern when processing nested brackets such that the remaining input length exceeds the output capacity. This issue has been addressed in release version 0.12.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Ubuntu Security Notice 7168-1 - It was discovered that EditorConfig improperly managed memory when handling certain inputs, leading to overflows. An attacker could possibly use these issues to cause a denial of service, or execute arbitrary code.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-11-22 CVE Reserved
- 2024-11-26 CVE Published
- 2024-11-27 CVE Updated
- 2024-11-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://editorconfig.org | X_refsource_misc | |
https://github.com/editorconfig/editorconfig-core-c/commit/4d5518a0a4e4910c37281ab13a048d0d86999782 | X_refsource_misc | |
https://github.com/editorconfig/editorconfig-core-c/commit/a8dd5312e08abeab95ff5656d32ed3cb85fba70b | X_refsource_misc | |
https://github.com/editorconfig/editorconfig-core-c/pull/103 | X_refsource_misc | |
https://github.com/editorconfig/editorconfig-core-c/security/advisories/GHSA-475j-wc37-6274 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Editorconfig Search vendor "Editorconfig" | Editorconfig-core-c Search vendor "Editorconfig" for product "Editorconfig-core-c" | < 0.12.7 Search vendor "Editorconfig" for product "Editorconfig-core-c" and version " < 0.12.7" | en |
Affected
|