CVE-2017-5357: Use After Free
Published Feb 16, 2017
·Updated
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
Affected Software
2 affected components
fedoraproject fedora=25
GNU ed<=1.14
Remediation
Patch Available
Event History
Feb 16, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 17, 2017
Data Sourced
via NVD·02:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5357?
CVE-2017-5357 has a severity level classified as medium, due to its potential to cause a denial of service.
2
How do I fix CVE-2017-5357?
To fix CVE-2017-5357, upgrade GNU ed to version 1.14.1 or later.
3
What versions of GNU ed are affected by CVE-2017-5357?
Versions of GNU ed prior to 1.14.1 are affected by CVE-2017-5357.
4
Can CVE-2017-5357 lead to data loss?
CVE-2017-5357 primarily causes a denial of service, but it does not directly lead to data loss.
5
Is CVE-2017-5357 specific to any operating systems?
CVE-2017-5357 affects GNU ed across various operating systems, including Fedora version 25.