CVE-2024-0684

A flaw was found in the GNU coreutils “split” program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

More information : https://access.redhat.com/security/cve/CVE-2024-0684

Attack vector : LOCAL
Attack complexity : LOW
Privileges required : LOW
User interaction : NONE
Confidentiality impact : NONE
Integrity impact : NONE
Base score : 5.5
Base severity : MEDIUM
Exploitability score : 1.8
Impact score : 3.6