CVE-2024-0911

NameCVE-2024-0911
DescriptionA flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1061543

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
indent (PTS)bullseye2.2.12-1+deb11u1fixed
bookworm2.2.12-4+deb12u3fixed
sid, trixie2.2.13-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
indentsourcebullseye2.2.12-1+deb11u1
indentsourcebookworm2.2.12-4+deb12u3
indentsource(unstable)2.2.13-4unimportant1061543

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2259883
https://bugzilla.redhat.com/show_bug.cgi?id=2260399
https://lists.gnu.org/archive/html/bug-indent/2024-01/msg00001.html
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems