The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
2015-02-12T16:59:03.707
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | grep | 2.19 | Yes |
Application | gnu | grep | 2.20 | Yes |
Application | gnu | grep | 2.21 | Yes |
Operating System | opensuse | opensuse | 13.2 | Yes |