First published: Thu Jan 24 2013(Updated: )
It was reported [1] that the sort command suffered from a segfault when processing input streams that contained extremely long strings when used with the -d and -M switches. This flaw is due to the inclusion of the coreutils-i18n.patch. SUSE has fixed this by fixing the patch. The changes can be seen here [2]. (There is probably e better place to get the patch, but I don't know where). [1] <a href="https://bugzilla.novell.com/show_bug.cgi?id=798538">https://bugzilla.novell.com/show_bug.cgi?id=798538</a> [2] <a href="https://build.opensuse.org/request/show/149348#diff_headline_coreutils-i18n-patch_diff_action_0_submit_0_19">https://build.opensuse.org/request/show/149348#diff_headline_coreutils-i18n-patch_diff_action_0_submit_0_19</a> Statement: (none)
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =6.0 | |
openSUSE | =12.1 | |
openSUSE | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0221 has a medium severity rating due to its potential to cause segmentation faults.
To fix CVE-2013-0221, ensure that you apply the latest patches from your operating system vendor.
CVE-2013-0221 affects Red Hat Enterprise Linux 6.0 and openSUSE versions 12.1 and 12.2.
The vulnerability CVE-2013-0221 is associated with the sort command when using the -d and -M switches.
The potential impacts of CVE-2013-0221 include application crashes and denial of service due to segmentation faults.