A vulnerability in grep could result in Denial of Service.
|Package||sys-apps/grep on all architectures|
|Affected versions||< 2.21-r1|
|Unaffected versions||>= 2.21-r1|
grep is the GNU regular expression matcher.
A heap buffer overrun has been fixed in the bmexec_trans function in kwset.c.
A local user can cause Denial of Service.
There is no known workaround at this time.
All grep users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/grep-2.21-r1"
February 25, 2015
February 25, 2015: 1