Out-of-bounds Write Affecting coreutils package, versions *
Threat Intelligence
EPSS
0.04% (6th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-COREUTILS-6180568
- published 19 Jan 2024
- disclosed 6 Feb 2024
Introduced: 19 Jan 2024
CVE-2024-0684 Open this link in a new tabHow to fix?
There is no fixed version for Debian:unstable
coreutils
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream coreutils
package and not the coreutils
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.
CVSS Scores
version 3.1