First published: Thu Jan 25 2024(Updated: )
A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU indent | =2.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0911 has a severity rating that indicates it poses a significant risk due to the potential for a heap-based buffer overflow.
To fix CVE-2024-0911, update GNU Indent to version 2.2.14 or later.
CVE-2024-0911 may allow an attacker to crash the application and potentially exploit the buffer overflow.
Users of GNU Indent version 2.2.13 are affected by CVE-2024-0911.
There is no officially recommended workaround for CVE-2024-0911 other than upgrading to a fixed version.