GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
{ "urgency": "not yet assigned" }