Heap-Based Buffer Overflow in GNU Coreutils Affects 64-Bit Platforms
CVE-2015-4041
7.8HIGH
What is CVE-2015-4041?
The keycompare_mb function within the sort component of GNU Coreutils versions up to 8.23 on 64-bit platforms is vulnerable due to inadequate size calculation for multibyte characters. This flaw can lead to a denial of service, resulting in a heap-based buffer overflow and potential application crashes. Attackers may exploit this vulnerability by delivering specially crafted long UTF-8 strings, which may disrupt service and could have additional unforeseen impacts.