Bug 914695 (CVE-2015-1345) - VUL-0: CVE-2015-1345: grep: -F heap buffer overrun
Summary: VUL-0: CVE-2015-1345: grep: -F heap buffer overrun
Status: RESOLVED FIXED
Alias: CVE-2015-1345
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Andreas Schwab
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113130/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-26 09:08 UTC by Victor Pereira
Modified: 2015-02-10 09:15 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-26 09:08:45 UTC
rh#1185440

It was reported [1] that invoking grep with a carefully crafted combination of input and regexp can cause a segfault and/or reading from uninitialized memory.

Upstream bugreport: http://bugs.gnu.org/19563
Upstream fix: http://git.sv.gnu.org/cgit/grep.git/commit/?id=83a95bd8c8561875b948cadd417c653dbe7ef2e2


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1183651
https://bugzilla.redhat.com/show_bug.cgi?id=1185440
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1345
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1345.html
Comment 1 Bernhard Wiedemann 2015-01-26 12:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (914695) was mentioned in
https://build.opensuse.org/request/show/282841 Factory / grep
Comment 2 Swamp Workflow Management 2015-01-26 23:00:25 UTC
bugbot adjusting priority
Comment 5 Swamp Workflow Management 2015-02-09 17:05:01 UTC
openSUSE-SU-2015:0243-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 914695
CVE References: CVE-2015-1345
Sources used:
openSUSE 13.2 (src):    grep-2.20-2.4.1