CVE-2012-5667: Buffer Overflow

Published Dec 24, 2012
·
Updated

An integer overflow leading to a heap-based buffer overflow was found in the way grep, A utility used to search through textual input for lines which contain a match to a specified pattern, parsed large lines of data. This flaw could use used to crash grep or potentially execute arbitrary code, if a local user was tricked into running grep on a specially crafted data file.

Patch: http://git.savannah.gnu.org/cgit/grep.git/commit/?id=cbbc1a45b9f843c811905c97c90a5d31f8e6c189 Reference: http://seclists.org/oss-sec/2012/q4/504

Other sources

Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

MITRE

Affected Software

19 affected componentsFixes available
redhat/grep<2.11
2.11
GNU Grep<=2.10
GNU Grep=2.2
GNU Grep=2.3
GNU Grep=2.4
GNU Grep=2.4.1
GNU Grep=2.4.2
GNU Grep=2.5
GNU Grep=2.5.1
GNU Grep=2.5.1-a
GNU Grep=2.5.3
GNU Grep=2.5.4
GNU Grep=2.6
GNU Grep=2.6.1
GNU Grep=2.6.2
GNU Grep=2.6.3
GNU Grep=2.7
GNU Grep=2.8
GNU Grep=2.9

Event History

Jan 3, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2012-5667?

CVE-2012-5667 has a severity rating that suggests it can lead to a heap-based buffer overflow, potentially allowing for arbitrary code execution.

2

How do I fix CVE-2012-5667?

To mitigate CVE-2012-5667, users should upgrade to grep version 2.11 or later.

3

Which versions of grep are affected by CVE-2012-5667?

Grep versions prior to 2.11, including but not limited to versions 2.2 through 2.10, are impacted by CVE-2012-5667.

4

What impact does CVE-2012-5667 have on system security?

CVE-2012-5667 can cause grep to crash and may permit the execution of arbitrary code, posing a significant security risk.

5

Is it safe to use grep versions before 2.11 due to CVE-2012-5667?

It is not safe to use grep versions prior to 2.11 as they are vulnerable to exploitation via CVE-2012-5667.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203