editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains many escaped characters. The added backslashes leave too little space in the output pattern when processing nested brackets such that the remaining input length exceeds the output capacity. This issue has been addressed in release version 0.12.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Wed, 27 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Editorconfig
Editorconfig editorconfig
CPEs cpe:2.3:a:editorconfig:editorconfig:*:*:*:*:*:*:*:*
Vendors & Products Editorconfig
Editorconfig editorconfig
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 23:45:00 +0000

Type Values Removed Values Added
Description editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains many escaped characters. The added backslashes leave too little space in the output pattern when processing nested brackets such that the remaining input length exceeds the output capacity. This issue has been addressed in release version 0.12.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Several stack buffer overflows and pointer overflows in editorconfig-core-c
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-26T23:34:58.784Z

Updated: 2024-11-27T15:35:10.367Z

Reserved: 2024-11-22T17:30:02.140Z

Link: CVE-2024-53849

cve-icon Vulnrichment

Updated: 2024-11-27T15:34:11.647Z

cve-icon NVD

Status : Received

Published: 2024-11-27T00:15:18.223

Modified: 2024-11-27T00:15:18.223

Link: CVE-2024-53849

cve-icon Redhat

No data.