A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade indent | Mar 21, 2024 | Feb 6, 2024 |
| Amazon Linux Ami 2 | — | Upgrade indent-debuginfoUpgrade indent | Feb 8, 2024 | Feb 6, 2024 |
| Amazon_linux_2023 | — | Upgrade indent-debugsourceUpgrade indent-debuginfoUpgrade indent | Feb 17, 2025 | Jan 23, 2024 |
| Debian | — | Upgrade indent | Jul 30, 2024 | Feb 6, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade indent | Jul 23, 2024 | Feb 6, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 6, 2024 |
| Suse | — | Upgrade indent-langUpgrade indent | Mar 22, 2024 | Feb 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub