Logo
componentgawk
Name
gawk
Version
5.1.1
Type
library
Description
GNU awk text processing utility
Licenses
GPL-3.0-only
PURL
-
CPE
cpe:2.3:*:*:gawk:5.1.1:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
5.4.1
scarthgap
5.3.0

Patches#


#
Title
Author
Resolve
1
Smal bug fix in builtin.c.
"Arnold D. Robbins" <arnold@skeeve.com>
CVE-2023-4156
2
Patch #2
Ross Burton <ross.burton@arm.com>

Vulnerabilities#


Name
Analysis
Description
Exploitable
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Exploitable
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Exploitable
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Exploitable
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
Patched
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.