LWN.net Logo

coreutils: multiple vulnerabilities

Package(s):coreutils CVE #(s):CVE-2013-0221 CVE-2013-0222 CVE-2013-0223
Created:February 1, 2013 Updated:April 5, 2013
Description:

From the Red Hat bugzilla entries [1, 2, 3]:

CVE-2013-0221: It was reported that the sort command suffered from a segfault when processing input streams that contained extremely long strings when used with the -d and -M switches. This flaw is due to the inclusion of the coreutils-i18n.patch.

CVE-2013-0222: It was reported that the uniq command suffered from a segfault when processing input streams that contained extremely long strings. This flaw is due to the inclusion of the coreutils-i18n.patch.

CVE-2013-0223: It was reported that the join command suffered from a segfault when processing input streams that contained extremely long strings when used with the -i switch. This flaw is due to the inclusion of the coreutils-i18n.patch.

Alerts:
Fedora FEDORA-2013-1455 2013-02-01
openSUSE openSUSE-SU-2013:0233-1 2013-02-04
openSUSE openSUSE-SU-2013:0232-1 2013-02-04
openSUSE openSUSE-SU-2013:0237-1 2013-02-04
Mageia MGASA-2013-0048 2013-02-13
Fedora FEDORA-2013-1804 2013-03-12
Mandriva MDVSA-2013:023 2013-03-13
Mandriva MDVSA-2013:023-1 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds