Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.
2013-01-03T11:54:25.417
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | grep | ≤ 2.10 | Yes |
Application | gnu | grep | 2.2 | Yes |
Application | gnu | grep | 2.3 | Yes |
Application | gnu | grep | 2.4 | Yes |
Application | gnu | grep | 2.4.1 | Yes |
Application | gnu | grep | 2.4.2 | Yes |
Application | gnu | grep | 2.5 | Yes |
Application | gnu | grep | 2.5.1 | Yes |
Application | gnu | grep | 2.5.1 | Yes |
Application | gnu | grep | 2.5.3 | Yes |
Application | gnu | grep | 2.5.4 | Yes |
Application | gnu | grep | 2.6 | Yes |
Application | gnu | grep | 2.6.1 | Yes |
Application | gnu | grep | 2.6.2 | Yes |
Application | gnu | grep | 2.6.3 | Yes |
Application | gnu | grep | 2.7 | Yes |
Application | gnu | grep | 2.8 | Yes |
Application | gnu | grep | 2.9 | Yes |