CVE Vulnerabilities

CVE-2012-5667

Published: Jan 03, 2013 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Grep Gnu * 2.10 (including)
Grep Gnu 2.2 (including) 2.2 (including)
Grep Gnu 2.3 (including) 2.3 (including)
Grep Gnu 2.4 (including) 2.4 (including)
Grep Gnu 2.4.1 (including) 2.4.1 (including)
Grep Gnu 2.4.2 (including) 2.4.2 (including)
Grep Gnu 2.5 (including) 2.5 (including)
Grep Gnu 2.5.1 (including) 2.5.1 (including)
Grep Gnu 2.5.1-a (including) 2.5.1-a (including)
Grep Gnu 2.5.3 (including) 2.5.3 (including)
Grep Gnu 2.5.4 (including) 2.5.4 (including)
Grep Gnu 2.6 (including) 2.6 (including)
Grep Gnu 2.6.1 (including) 2.6.1 (including)
Grep Gnu 2.6.2 (including) 2.6.2 (including)
Grep Gnu 2.6.3 (including) 2.6.3 (including)
Grep Gnu 2.7 (including) 2.7 (including)
Grep Gnu 2.8 (including) 2.8 (including)
Grep Gnu 2.9 (including) 2.9 (including)
Red Hat Enterprise Linux 6 RedHat grep-0:2.20-3.el6 *
Grep Ubuntu hardy *
Grep Ubuntu lucid *
Grep Ubuntu oneiric *
Grep Ubuntu precise *
Grep Ubuntu precise/esm *
Grep Ubuntu upstream *

References