Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade grep | Jul 30, 2024 | Jan 3, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 29, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/grep. | Oct 30, 2017 | Jan 3, 2013 |
| Oracle Solaris | — | Upgrade text/gnu-grep to version 2.14-0.175.1.7.0.2.0 on Solaris 11.1 | May 29, 2017 | Jan 3, 2013 |
| Oracle_linux | — | Upgrade grep | Oct 16, 2024 | Jan 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub