CVE-2023-4156

A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
redhatCNA
4.4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
gnugawk
𝑥
< 5.1.1
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gawk
bullseye
no-dsa
buster
postponed
trixie
1:5.2.1-2
fixed
bookworm
1:5.2.1-2
fixed
sid
1:5.2.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gawk
mantic
not-affected
lunar
not-affected
jammy
Fixed 1:5.1.0-1ubuntu0.1
released
focal
Fixed 1:5.0.1+dfsg-1ubuntu0.1
released
bionic
Fixed 1:4.1.4+dfsg-1ubuntu0.1~esm1
released
xenial
Fixed 1:4.1.3+dfsg-0.1ubuntu0.1~esm1
released
trusty
Fixed 1:4.0.1+dfsg-2.1ubuntu2+esm1
released