HIGH
Stack Buffer Overflow in editorconfig-core-c
Published Jan 31, 2023
7.8
HIGHCVSS 3.1
EPSS 0.97%
Description
A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write operations over the p_pcre buffer.
Affected products
-
- Version 0StatusaffectedConstraints<v0.12.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| EditorConfig | EditorConfig C Core | n/a |
|
- < 0.12.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12402 Advisory
- https://github.com/editorconfig/editorconfig-core-c/commit/41281ea82fbf24b060a9f69b9c5369350fb0529e patchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/11/msg00036.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZCFE7DXWAAKDJPRKMXHCACKGKNV37IYZ/
- https://litios.github.io/2023/01/14/CVE-2023-0341.html technical-descriptionExploitPatchThird Party Advisory
- https://ubuntu.com/security/notices/USN-5842-1 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12402 | Advisory | |
| https://github.com/editorconfig/editorconfig-core-c/commit/41281ea82fbf24b060a9f69b9c5369350fb0529e | patchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/11/msg00036.html | ||
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZCFE7DXWAAKDJPRKMXHCACKGKNV37IYZ/ | ||
| https://litios.github.io/2023/01/14/CVE-2023-0341.html | technical-descriptionExploitPatchThird Party Advisory | |
| https://ubuntu.com/security/notices/USN-5842-1 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jan 31, 2023
Updated Nov 3, 2025
Reserved Jan 17, 2023
Link CVE-2023-0341
CISA Vulnrichment
Updated Mar 27, 2025
ENISA EUVD
EUVD-2023-12402 Assigner canonical
Published Jan 31, 2023
Updated Nov 3, 2025
Exploited since n/a
Link EUVD-2023-12402