跳转到帖子

Ubuntu: USN-7168-1 (CVE-2024-53849): EditorConfig vulnerabilities

recommended_posts

发布于
  • Members

Ubuntu: USN-7168-1 (CVE-2024-53849): EditorConfig vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
11/27/2024
Created
12/20/2024
Added
12/19/2024
Modified
12/19/2024

Description

editorconfig-core-cistheEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains many escaped characters. The added backslashes leave too little space in the output pattern when processing nested brackets such that the remaining input length exceeds the output capacity. This issue has been addressed in release version 0.12.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Solution(s)

  • ubuntu-pro-upgrade-editorconfig
  • ubuntu-pro-upgrade-libeditorconfig0

References

  • https://attackerkb.com/topics/cve-2024-53849
  • CVE - 2024-53849
  • USN-7168-1
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…