DEBIAN-CVE-2006-0459

Source
https://security-tracker.debian.org/tracker/CVE-2006-0459
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-0459.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2006-0459
Upstream
Published
2006-03-29T23:02:00Z
Modified
2025-11-19T01:01:56.147820Z
Summary
[none]
Details

flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.

References

Affected packages

Debian:11 / flex

Package

Name
flex
Purl
pkg:deb/debian/flex?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-0459.json"

Debian:12 / flex

Package

Name
flex
Purl
pkg:deb/debian/flex?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-0459.json"

Debian:13 / flex

Package

Name
flex
Purl
pkg:deb/debian/flex?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-0459.json"

Debian:14 / flex

Package

Name
flex
Purl
pkg:deb/debian/flex?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-0459.json"