Unrated severityNVD Advisory· Published Jan 24, 2020· Updated Aug 6, 2024
CVE-2015-4041
CVE-2015-4041
Description
The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- GNU/Coreutilsdescription
- osv-coords4 versionspkg:rpm/opensuse/coreutils&distro=openSUSE%20Tumbleweedpkg:rpm/suse/coreutils&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/coreutils&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/coreutils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012
< 8.26-1.1+ 3 more
- (no CPE)range: < 8.26-1.1
- (no CPE)range: < 8.22-9.1
- (no CPE)range: < 8.22-9.1
- (no CPE)range: < 8.22-9.1
Patches
Vulnerability mechanics
References
3- openwall.com/lists/oss-security/2015/05/15/1mitrex_refsource_MISC
- bugzilla.suse.com/show_bug.cgimitrex_refsource_MISC
- github.com/pixelb/coreutils/commit/bea5e36cc876ed627bb5e0eca36fdfaa6465e940mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.