CVE-2015-4042: Integer Overflow
Published Jan 24, 2020
·Updated
Integer overflow in the keycomparemb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.
Affected Software
1 affected component
GNU Coreutils<=8.23
Remediation
Patch Available
Event History
Jan 24, 2020
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4042?
CVE-2015-4042 has a medium severity level due to its potential to cause application crashes.
2
How do I fix CVE-2015-4042?
To fix CVE-2015-4042, upgrade to GNU Coreutils version 8.24 or later.
3
What systems are vulnerable to CVE-2015-4042?
CVE-2015-4042 affects GNU Coreutils versions up to and including 8.23.
4
What impact could CVE-2015-4042 have on my system?
CVE-2015-4042 could result in a denial of service attack or cause the application to crash.
5
Is CVE-2015-4042 actively being exploited?
As of now, there are no public reports of active exploitation related to CVE-2015-4042.