Candidate: CVE-2015-1345 PublicDate: 2015-02-12 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1345 Description: The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option. Ubuntu-Description: Notes: mdeslaur> introduced in v2.18-90-g73893ff Bugs: http://bugs.gnu.org/19563 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776039 Priority: low Discovered-by: Nima Aghdaii and Yuliy Pisetsky Assigned-to: CVSS: Patches_grep: upstream: http://git.savannah.gnu.org/cgit/grep.git/commit/?id=83a95bd8c8561875b948cadd417c653dbe7ef2e2 upstream_grep: released (2.20-4.1) lucid_grep: not-affected (2.5.4-4build1) precise_grep: not-affected (2.10-1) trusty_grep: not-affected (2.16-1) trusty/esm_grep: not-affected (2.16-1) vivid/stable-phone-overlay_grep: not-affected (2.20-4.1) vivid/ubuntu-core_grep: not-affected (2.20-4.1) wily_grep: not-affected (2.21-2) xenial_grep: not-affected (2.24-1) esm-infra/xenial_grep: not-affected (2.24-1) devel_grep: not-affected