A vulnerability in grep could result in Denial of Service.
Package | sys-apps/grep on all architectures |
---|---|
Affected versions | < 2.21-r1 |
Unaffected versions | >= 2.21-r1 |
grep is the GNU regular expression matcher.
A heap buffer overrun has been fixed in the bmexec_trans function in kwset.c.
A local user can cause Denial of Service.
There is no known workaround at this time.
All grep users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/grep-2.21-r1"
Release date
February 25, 2015
Latest revision
February 25, 2015: 1
Severity
normal
Exploitable
local
Bugzilla entries