CVE-2015-1345: Buffer Overflow
Published Feb 12, 2015
·Updated
The bmexectrans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
Affected Software
4 affected components
GNU Grep=2.19
GNU Grep=2.20
GNU Grep=2.21
openSUSE openSUSE=13.2
Event History
Feb 12, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1345?
CVE-2015-1345 is classified as a denial of service vulnerability, allowing local users to cause a crash.
2
How do I fix CVE-2015-1345?
To fix CVE-2015-1345, upgrade GNU Grep to version 2.22 or later.
3
Which versions of grep are affected by CVE-2015-1345?
CVE-2015-1345 affects GNU Grep versions 2.19 through 2.21.
4
Can CVE-2015-1345 be exploited remotely?
No, CVE-2015-1345 requires local user access to exploit.
5
What happens if I don't address CVE-2015-1345?
If not addressed, CVE-2015-1345 could lead to application crashes due to crafted input.