Releases386
Frequency1 month 1 week
Last Release
Stars2
dev branches

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH4.6 MEDIUM

The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.

9.8 CRITICAL7.5 HIGH

Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.