OESA-2023-1552
Dashboard / Vulnerabilities / OESA-2023-1552
Summary: indent security update
Details: The indent program can be used to make code easier to read. It can also convert from one style of writing C to another. indent understands a substantial amount about the syntax of C, but it also attempts to cope with incomplete and misformed syntax. Security Fix(es): GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.(CVE-2023-40305)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1552, https://nvd.nist.gov/vuln/detail/CVE-2023-40305
Affected packages
Package
Name: indent
Purl: pkg:rpm/openEuler/indent&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.2.11-29.oe1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
