CVE-2024-0911
Indent: heap-based buffer overflow in set_buf_break()
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
indentReferences
https://access.redhat.com/security/cve/CVE-2024-0911https://bugzilla.redhat.com/show_bug.cgi?id=2260399https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYVDWBSJROWOWMPDVMVG4L5FGVJC5REN/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIEHMOQDLPRTE4FDOA4X6PMOCNLK6BCP/https://lists.gnu.org/archive/html/bug-indent/2024-01/msg00000.html