PT-2023-27372 · Gnu+3 · Gnu Indent+3

Yisumi

+1

·

Published

2023-08-13

·

Updated

2026-03-29

·

CVE-2023-40305

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU indent version 2.2.13
Description The issue is a heap-based buffer overflow in the search brace function in indent.c via a crafted file. Additionally, there is a heap overread in the lexi() function.
Recommendations For GNU indent version 2.2.13, as a temporary workaround, consider disabling the search brace function and restricting the use of the lexi() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43837
AZL-45015
CVE-2023-40305
MGASA-2023-0274
OESA-2023-1552
OPENSUSE-SU-2023_3433-1
OPENSUSE-SU-2024:13149-1
SUSE-SU-2023:3432-1
SUSE-SU-2023:3433-1
SUSE-SU-2023_3432-1
SUSE-SU-2023_3433-1
USN-6389-1

Affected Products

Gnu Indent
Linuxmint
Suse
Ubuntu