CVE-2023-40305: Buffer Overflow
GNU indent 2.2.13 has a heap-based buffer overflow in searchbrace in indent.c via a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-40305.
What is the severity of CVE-2023-40305?
The severity of CVE-2023-40305 is medium with a CVSS score of 5.5.
How does CVE-2023-40305 impact GNU indent?
CVE-2023-40305 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, resulting in a heap-based buffer overflow in the search_brace function in indent.c.
How can I fix CVE-2023-40305 on GNU indent version 2.2.13?
To fix the vulnerability, you should update GNU indent to version 2.2.13-3 or later.
Where can I find more information about CVE-2023-40305?
You can find more information about CVE-2023-40305 at the following references: [Reference 1](https://ftp.gnu.org/gnu/indent/), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3W6SL3NKMH5R4S5PD2O3MTC2UR4SBVHK/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MIUH3F63KQJWYR3FLKRZUYYRJOY6FYX/).