CVE-2023-40305

Name
CVE-2023-40305
Description
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://ftp.gnu.org/gnu/indent/
MISC https://savannah.gnu.org/bugs/index.php?64503
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W6SL3NKMH5R4S5PD2O3MTC2UR4SBVHK/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4MIUH3F63KQJWYR3FLKRZUYYRJOY6FYX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OB6GB6FUFPV5VJAZIANDG4YNNDW6JNXX/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:indent:2.2.13:*:*:*:*:*:*:* indent == None == 2.2.13

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
indent edge-main 2.2.13-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
indent 3.18-main 2.2.13-r1 None possibly vulnerable
indent 3.19-main 2.2.13-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable