First published: Thu Feb 16 2017(Updated: )
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =25 | |
GNU ed | <=1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5357 has a severity level classified as medium, due to its potential to cause a denial of service.
To fix CVE-2017-5357, upgrade GNU ed to version 1.14.1 or later.
Versions of GNU ed prior to 1.14.1 are affected by CVE-2017-5357.
CVE-2017-5357 primarily causes a denial of service, but it does not directly lead to data loss.
CVE-2017-5357 affects GNU ed across various operating systems, including Fedora version 25.