OESA-2023-1575
Dashboard / Vulnerabilities / OESA-2023-1575
Summary: gawk security update
Details: The gawk package is the GNU implementation of awk. The awk utility interprets a special-purpose programming language that makes it possible to handle simple data-reformatting jobs with just a few lines of code. Security Fix(es): A heap out of bound read issue exists in builtin.c of gawk prior to version 5.1.1. The array "the_args" takes an unsafe index "val", while it does not validate the index to ensure the index refers to a valid position in the array (e.g., exceedingly large or negative). The vulnerability can cause crash of the software and might be used by attackers to read sensitive information. https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html https://fossies.org/linux/gawk/ChangeLog#470 (Line: 470-475)(CVE-2023-4156)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1575, https://nvd.nist.gov/vuln/detail/CVE-2023-4156
Affected packages
Package
Name: gawk
Purl: pkg:rpm/openEuler/gawk&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
