The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade coreutils | Jul 30, 2024 | Jan 16, 2015 |
| Gentoo Linux | — | Upgrade sys-apps/coreutils. | Oct 30, 2017 | Jan 16, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 25, 2014 |
| Suse | — | Upgrade coreutils-x86Upgrade coreutilsUpgrade coreutils-lang | Dec 18, 2015 | Jan 16, 2015 |
| Ubuntu | — | Upgrade coreutils | Nov 8, 2024 | Jan 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub