Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "augeas-lenses",
"binary_version": "1.2.0-0ubuntu1.3"
},
{
"binary_name": "augeas-tools",
"binary_version": "1.2.0-0ubuntu1.3"
},
{
"binary_name": "libaugeas-dev",
"binary_version": "1.2.0-0ubuntu1.3"
},
{
"binary_name": "libaugeas0",
"binary_version": "1.2.0-0ubuntu1.3"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "augeas-lenses",
"binary_version": "1.4.0-0ubuntu1.1"
},
{
"binary_name": "augeas-tools",
"binary_version": "1.4.0-0ubuntu1.1"
},
{
"binary_name": "libaugeas-dev",
"binary_version": "1.4.0-0ubuntu1.1"
},
{
"binary_name": "libaugeas0",
"binary_version": "1.4.0-0ubuntu1.1"
}
]
}